PT-2012-1302 · Microsoft+1 · Help/Support Center+1
Publicado
2012-08-22
·
Atualizado
2012-08-22
·
CVE-2010-3497
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Symantec Norton AntiVirus version 2011
Description
The issue arises from improper interaction with the Microsoft Help and Support Center's processing of hcp:// URLs, allowing remote attackers to execute arbitrary code. This occurs even when the malware is correctly detected, but the detection happens too late to prevent code execution.
Recommendations
For Symantec Norton AntiVirus version 2011, consider restricting access to hcp:// URLs in the Microsoft Help and Support Center as a temporary mitigation measure until a fix is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Help/Support Center
Symantec Norton Antivirus