PT-2004-1518 · Symantec · Norton Internet Security
Mark Litchfield
·
Published
2004-03-23
·
Updated
2017-07-11
·
CVE-2004-0364
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Norton Internet Security version 2004
Description
The issue concerns the WrapNISUM ActiveX component, specifically the WrapUM.dll file, which is marked as safe for scripting. This marking allows remote attackers to execute arbitrary programs by utilizing the LaunchURL method.
Recommendations
For Norton Internet Security version 2004, consider disabling the WrapUM.dll file or restricting its use to prevent exploitation until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Norton Internet Security