----- Original Message ----- 
From: "Secunia Security Advisories" <[EMAIL PROTECTED]>


TITLE:
Symantec Norton AntiVirus Unprivileged Auto-Protection Deactivation

SECUNIA ADVISORY ID:
SA12863

VERIFY ADVISORY:
http://secunia.com/advisories/12863/

CRITICAL:
Less critical

IMPACT:
Privilege escalation

WHERE:
Local system

SOFTWARE:
Norton Internet Security 2004
http://secunia.com/product/2441/
Norton Internet Security 2004 Professional
http://secunia.com/product/2442/
Symantec Norton AntiVirus 2004
http://secunia.com/product/2800/

DESCRIPTION:
A vulnerability in Symantec Norton AntiVirus / Norton Internet Security,
which can be exploited by malicious, local users to disable the
auto-protection.

The vulnerability is caused due to an error in the auto-protection
functionality when dealing with certain visual basic scripts. This
can be exploited by a unprivileged user to force the auto-protection
to be disabled for the current session.

This can further be exploited to e.g. download and execute malicious
files which normally would be caught by the antivirus program.

The vulnerability has been confirmed on Norton Internet Security
2004. Other versions may also be affected.

SOLUTION:
Grant only trusted users access to the system or use another product.
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/rules.htm
Contact list owner <[EMAIL PROTECTED]>
Unsubscribing and other changes: http://pcworkers.com
=====================================================

Reply via email to