Advertisement
Promo

Security threats Toolkit

Symantec announces ActiveX vulnerability

Richard Thurston ZDNet.co.uk

Published: 10 Aug 2007 16:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Symantec has revealed details of a vulnerability in two ActiveX controls used in its Norton Windows antivirus software.

The vulnerability was reported by security research firm Secunia as "highly critical" and Symantec urged users to update their software immediately.

Norton AntiVirus 2006, Norton Internet Security 2006, Norton SystemWorks 2006 and Norton Internet Security 2005 AntiSpyware Edition are affected.

Symantec's corporate security software is not affected.

The problem in the ActiveX controls could allow a hacker to execute code on an affected PC.

It comes about because of an input validation error, which fails to analyse incoming data for malicious commands before executing them.

To exploit the vulnerability, hackers could send emails to users inviting them to click on a link to a website containing the exploit code, Symantec said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
32 out of 32 people found this useful



Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

2 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters