PT-2018-16829 · Symantec · Norton Power Eraser+1
Publicado
2018-08-22
·
Atualizado
2018-11-14
·
CVE-2018-5238
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Norton Power Eraser versions prior to 5.3.0.24
SymDiag versions prior to 2.1.242
Description
The issue is related to a DLL Preloading vulnerability, which occurs when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. This can be exploited by a simple file write, resulting in a foreign DLL running under the context of the application.
Recommendations
For Norton Power Eraser versions prior to 5.3.0.24, update to version 5.3.0.24 or later.
For SymDiag versions prior to 2.1.242, update to version 2.1.242 or later.
Correção
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Norton Power Eraser
Symdiag