PT-2007-1162 · Symantec+1 · Symantec Norton Antivirus+1

Published

2007-05-11

·

Updated

2017-07-20

·

CVE-2006-3456

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Symantec Norton AntiVirus versions 12.2.0.13
Description: The Symantec NAVOPTS.DLL ActiveX control is vulnerable to an issue that allows remote attackers to crash the control via unspecified vectors related to content on a web site. This can place Internet Explorer into a defunct state, allowing remote attackers to execute arbitrary code in addition to other Symantec ActiveX controls, regardless of whether they are marked safe for scripting.
Recommendations: For Symantec Norton AntiVirus version 12.2.0.13, consider disabling the NAVOPTS.DLL ActiveX control until a patch is available to prevent potential exploitation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-3456

Affected Products

Internet Explorer
Symantec Norton Antivirus