PT-2007-4921 · Symantec · Norton Antispam+6

Published

2007-07-15

·

Updated

2017-07-29

·

CVE-2007-3673

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec AntiVirus Corporate Edition versions 9 through 10.1 Symantec Client Security versions 2.0 through 3.1 Norton AntiSpam version 2005 Norton AntiVirus versions 2005 and 2006 Norton Internet Security versions 2005 and 2006 Norton Personal Firewall versions 2005 and 2006 Norton System Works versions 2005 and 2006 symtdi.sys version prior to 7.0.0
Description The issue allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to symTDI, resulting in memory overwrite.
Recommendations For Symantec AntiVirus Corporate Edition versions 9 through 10.1, update symtdi.sys to version 7.0.0 or later. For Symantec Client Security versions 2.0 through 3.1, update symtdi.sys to version 7.0.0 or later. For Norton AntiSpam version 2005, update symtdi.sys to version 7.0.0 or later. For Norton AntiVirus versions 2005 and 2006, update symtdi.sys to version 7.0.0 or later. For Norton Internet Security versions 2005 and 2006, update symtdi.sys to version 7.0.0 or later. For Norton Personal Firewall versions 2005 and 2006, update symtdi.sys to version 7.0.0 or later. For Norton System Works versions 2005 and 2006, update symtdi.sys to version 7.0.0 or later. For symtdi.sys version prior to 7.0.0, update to version 7.0.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3673

Affected Products

Norton Antispam
Norton Antivirus
Norton Internet Security
Norton Personal Firewall
Norton Systemworks
Symantec Antivirus Corporate Edition
Symantec Client Security