PT-2004-1518 · Symantec · Norton Internet Security
Mark Litchfield
·
Publicado
2004-03-23
·
Atualizado
2017-07-11
·
CVE-2004-0364
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Norton Internet Security version 2004
Description
The issue concerns the WrapNISUM ActiveX component, specifically the WrapUM.dll file, which is marked as safe for scripting. This marking allows remote attackers to execute arbitrary programs by utilizing the LaunchURL method.
Recommendations
For Norton Internet Security version 2004, consider disabling the WrapUM.dll file or restricting its use to prevent exploitation until a fix is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Norton Internet Security