Symantec slams the door on Live Update flaw
Published: 13 Jan 2004 16:55 GMT
Security company Symantec, developer of the popular Norton AntiVirus software, fixed a problem in its Live Update feature last week - a vulnerability that could allow malicious users to gain unauthorised administrator access rights to an affected PC.
Live Update is a feature Symantec's customers use in order to keep their virus signatures and security applications up to date. It can be set to automatically connect to the Internet and check Symantec's servers for a newer version. If one is found, the software can either prompt the user or automatically download and install the update, which is the recommended setting.
According to Symantec, the problem only affects Windows versions of its software and is rather obscure, requiring "a number of conditions" to be in place before it can be exploited. If an application has been set up in multi-user mode, with privileged and non-privileged access rights, it is possible for a non-privileged user to access and manipulate the Automatic Live Update interface in order to gain privileged access to the host computer.
The vulnerability, which was discovered by US-based consultants Secure Network Operations, was published on Tuesday, by which time Symantec had already fixed the problem by making a new version (2.0) of its Live Update feature available to download.
Symantec said the latest version of the update engine will be "automatically installed on a user's machine as soon as the computer connects to the Internet." If automatic live update has been disabled, users can use still Live Update to download and install the 4MB patch as soon as possible.
This is the second embarrassing episode for Symantec in a matter of days. Last Friday, Symantec's support forums were flooded with Norton AntiVirus users complaining of slow and unstable computers after the latest signature updates.
Full Talkback thread
122 comments
-
Why does my iMac with 10.2.8 keep coming up with m... Anonymous -
Why does my ME windows have trouble connecting wit... Anonymous -
Symantec has more than one Live Update flaw, in my... Anonymous -
I deleted Norton antivirus software from my PC and... Anonymous -
I am dumping Symantec products completely. Th... Anonymous -
I have Norton however, I don't know how run on-lin... Anthony Panzica -
OK. I take it back. GO TO...
"Step 5: Rena... cmthomas -
I did the following steps...it seemed to... Anonymous -
Talk about a program getting worse with time inste... Shawn -
why can't I get this thing to print the memo about... Anonymous -
I cannot get a liveupdate from symantec after down... William Marshall -
I had exactly the same problem! I am not impr... Iain Hepburn -
I never had problems with liveupdate UNT... Anonymous -
This is too wierd: I not only canno... Sandra -
Norton Anti Virus 2005. Not only are th... Anonymous -
I have the same problem as everyone... Stephen Skirving -
My solution for fixing the pro... Anonymous -
I keep getting a message that live update can... Anonymous -
I cannot get a liveupdate from symantec after down... Anonymous -
hello i am from holland enschede. I get the s... overbeek -
I have been trying to update my norton antivirus s... Jack Sevakian -
I cannot get Live Update to run either. Afte... Anonymous -
I too can not get the symantec live upda... Anonymous -
I cant update since I renewed my su... Anonymous -
Sometimes you have to use spec... Lannie Haven -
We have got 'LU1814 Live Updat... Frances Smith -
Had problems with LU1814 last... Dave McCoy -
In my opinion Norton is genera... Anonymous -
I've had the Symantec Update L... Anonymous -
Yesterday I received an e-mail... Anonymous -
Potential LU1814 solution...
I... Katrina -
LU1814 and Zone Alarm, July 20... Doug Godbee -
Have you tried this update:
ht... Mark Hendrixson -
I tried the update and it did... Bruce -
After many attemps to resolve... CM Thomas -
Title: 'Error: "LU1814: LiveUp... Anonymous -
LU1814 on Norton AntiVirus2005... Anonymous -
Each time I start up Windows,... Joshua Lee -
if your'e running windows 98 .... anonymous -
Same issue here. I'm looking... Murray -
Do a google search using Norto... Anonymous -
Here is what worked for me:
ht... D Romej -
The delete of the files you re... bubba -
Yup this one works
http://tiny... Anonymous -
I fixed it by doing two things... TheOldPig -
Ok people, this resolved the L... Anonymous -
Thanks to whomever suggested t... Craig Tucker -
Zone Alarm firewall caused LU1... Anonymous -
YES!! Deleting the file 'S32lu... Anonymous -
I renamed s32luhl1.dll to *.ol... Anonymous -
Dear Anon, it tech
your soluti... Don -
This worked for me too. Thank... Jim -
This worked for me too
Go to \... Anonymous -
Thank you for your solution fo... Anonymous -
cheers mate renaming this file... ROMEO -
Renaming the file worked Anonymous -
Works great. I just renamed it... Adrian -
Excellent. Thanks a lot - tha... Mark -
Hey thanks a lot. that worked... Anonymous -
Recently upgraded to Symantec... Anonymous -
Well done! Best fix ever! Been... Stephen Walsh -
I had the LU1814 problem also.... John Dodger -
I just wanted to say thanks to... Anonymous -
This worked for me.
1. Open th... Anonymous -
your file rename worked for me... Anonymous -
After trying everything possib... Wally -
I dont have the file s32LUHL1.... vickie -
Your solution to rename the fi... Anonymous -
This solution is simple and it... Phil Zern -
Thanks a million to "Novice Te... AJ -
Can someone help please. I als... Anonymous -
I am the previous poster and w... Anonymous -
I'm having the same problem, h... walt -
I was getting ready to roll up... Anonymous -
From above - this worked for m... Anonymous -
It worked! It worked! Took 6... Anonymous -
Same issue with Norton firewal... Anonymous -
I extremely grateful to whoeve... Anonymous -
Thank you, Novice Tech, whoeve... Anonymous -
This also worked for me!
Thank... Anonymous -
This is GENIUS! Symantec needs... mh -
Perfect fix. Thanks
One stupid... TL -
Thanks Buddy... It works... wa... Rakesh Virwar -
This worked for LU1814 problem... vasiya -
Dear Frances and Others,
I exp... Lohit Tutupalli -
Thanks so much Lohit Tutupalli... Bonnie Smith -
I have the same problem. For 3... Anonymous -
>Never failed to get Norton ba... rich herzog -
I think one problem that some... Robin -
I am another user that cannot... Carol Pike -
Hi People try this following t... Nischay Mehta -
Downloaded Nortons Internet Se... Regina Clayton -
I just renewed my Norton Antiv... Anonymous -
Here is a solution that worked for... Mark Hendrxson -
The solution posted by Mark He... Alan Worthington -
I updated to Internet 2005 las... Anonymous -
You have a virus on your computer. Do your wi... joe -
I have the same problem which started when I... Matt Masella -
This is becoming a serious issue lately.... Mike -
Purchased renewal for subscription... bill eff -
I've had the same issue - I've... Anonymous -
Name: Anonymous
Occupation:... Anonymous -
Our LU1814 problem was solved... Anonymous -
your missing your ccCommon.msi file... Anonymous -
I am so happy to find out that I am not the only o... Jennifer Thompson -
I guess I am not alone error # 1814. I have printe... Frank -
I am having problems with Norton Antivirus Live up... Donald G. Mascia -
I also had a problem after installing one of... Brian Clarke -
i just installed norton anti virus 2006.every... john digger -
I think i'm havind similar problems. I t... jamal -
Installed Internet Security 2006 on April 1.... Anonymous -
I had the same problem.
A solution appeared in the... Anonymous -
This worked for me.
I had successfully cleaned W3... Anonymous -
I have been trying all week to run Live Update bec... Anonymous -
i have had nis 2005 for three months . everything... anonymous -
i have had nis 2005 for three months . everything... anonymous -
Yes I had the same, I did 6 re-installs and... David Smith -
If you cannot install live updates go to lusetup s... Anonymous -
fantastic, tried all the things that Symantec sugg... Peter Wood -
Great tip...thank you. Anonymous -
Hey out there, Can you help me fix my live update.... Anonymous -
I have Norton internet security 2006 and am unable... Anonymous


