PT-2006-4590 · Symantec · Norton Personal Firewall

David Matousek

·

Published

2006-07-19

·

Updated

2018-10-17

·

CVE-2006-3725

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Norton Personal Firewall 2006 version 9.1.0.33
Description The issue allows local users to cause a denial of service, resulting in a crash, by performing certain operations on specific registry keys. These operations include RegSaveKey, RegRestoreKey, and RegDeleteKey on the HKLMSYSTEMCurrentControlSetServicesSNDSrvc and HKLMSYSTEMCurrentControlSetServicesSymEvent registry keys.
Recommendations For Norton Personal Firewall 2006 version 9.1.0.33, consider restricting access to the HKLMSYSTEMCurrentControlSetServicesSNDSrvc and HKLMSYSTEMCurrentControlSetServicesSymEvent registry keys to minimize the risk of exploitation. Avoid using the RegSaveKey, RegRestoreKey, and RegDeleteKey operations on these keys until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3725

Affected Products

Norton Personal Firewall