PT-2007-4921 · Symantec · Norton Antispam+6
Published
2007-07-15
·
Updated
2017-07-29
·
CVE-2007-3673
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Symantec AntiVirus Corporate Edition versions 9 through 10.1
Symantec Client Security versions 2.0 through 3.1
Norton AntiSpam version 2005
Norton AntiVirus versions 2005 and 2006
Norton Internet Security versions 2005 and 2006
Norton Personal Firewall versions 2005 and 2006
Norton System Works versions 2005 and 2006
symtdi.sys version prior to 7.0.0
Description
The issue allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to symTDI, resulting in memory overwrite.
Recommendations
For Symantec AntiVirus Corporate Edition versions 9 through 10.1, update symtdi.sys to version 7.0.0 or later.
For Symantec Client Security versions 2.0 through 3.1, update symtdi.sys to version 7.0.0 or later.
For Norton AntiSpam version 2005, update symtdi.sys to version 7.0.0 or later.
For Norton AntiVirus versions 2005 and 2006, update symtdi.sys to version 7.0.0 or later.
For Norton Internet Security versions 2005 and 2006, update symtdi.sys to version 7.0.0 or later.
For Norton Personal Firewall versions 2005 and 2006, update symtdi.sys to version 7.0.0 or later.
For Norton System Works versions 2005 and 2006, update symtdi.sys to version 7.0.0 or later.
For symtdi.sys version prior to 7.0.0, update to version 7.0.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Norton Antispam
Norton Antivirus
Norton Internet Security
Norton Personal Firewall
Norton Systemworks
Symantec Antivirus Corporate Edition
Symantec Client Security