E-Mail:
Author Avatar

Symantec AntiVirus Vulnerability

Local exploitation of a design error vulnerability in Symantec Corp. AntiVirus can allow an attacker to execute arbitrary code with kernel privileges.

The vulnerability specifically exists due to improper address space validation when the NAVENG and NAVEX15 device drivers process IOCTL 0×222AD3, 0×222AD7, and 0×222ADB. An attacker can overwrite a user supplied address, including code segments, with a constant double word value by supplying a specially crafted Irp to the IOCTL handler function.

ANALYSIS
Successful exploitation allows an attacker to obtain elevated privileges by exploiting the kernel. This could allow the attacker to gain control of the affected system. However, local access is required for exploitation to be successful…

VENDOR RESPONSE
Symantec has released updated device drivers via LiveUpdate. More information regarding this issue can be found in Symantec’s Advisory SYM06-020.

What Do You Think?

 


Anti-Spam Image

Want to Start a Blog Here for Free?

Are you an expert in one subject or another? If your goal is to help others and dispense hard-earned information back to the community, stake a claim on your very own Lockergnome blog today! You can write about anything - no matter the topic. Sign-up to start blogging!

Author Avatar
Download, Freeware - Sep 5, 2008

ThunderBrowse v3.2.1.9

Author Avatar
Download, Freeware - Sep 1, 2008

BitMeter v3.5.7

69 queries / 0.419 seconds.