PT-2006-4590 · Symantec · Norton Personal Firewall
David Matousek
·
Published
2006-07-19
·
Updated
2018-10-17
·
CVE-2006-3725
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Norton Personal Firewall 2006 version 9.1.0.33
Description
The issue allows local users to cause a denial of service, resulting in a crash, by performing certain operations on specific registry keys. These operations include RegSaveKey, RegRestoreKey, and RegDeleteKey on the HKLMSYSTEMCurrentControlSetServicesSNDSrvc and HKLMSYSTEMCurrentControlSetServicesSymEvent registry keys.
Recommendations
For Norton Personal Firewall 2006 version 9.1.0.33, consider restricting access to the HKLMSYSTEMCurrentControlSetServicesSNDSrvc and HKLMSYSTEMCurrentControlSetServicesSymEvent registry keys to minimize the risk of exploitation. Avoid using the
RegSaveKey, RegRestoreKey, and RegDeleteKey operations on these keys until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Norton Personal Firewall