PT-2010-1928 · Symantec · Symantec Client Security+2

Published

2010-02-19

·

Updated

2018-10-30

·

CVE-2010-0108

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec AntiVirus versions 10.0.x through 10.1.x before MR9 Symantec AntiVirus versions 10.2.x before MR4 Symantec Client Security versions 3.0.x through 3.1.x before MR9
Description The issue is related to a buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy. This allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.
Recommendations For Symantec AntiVirus versions 10.0.x through 10.1.x before MR9, update to MR9 or later. For Symantec AntiVirus versions 10.2.x before MR4, update to MR4 or later. For Symantec Client Security versions 3.0.x through 3.1.x before MR9, update to MR9 or later.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0108

Affected Products

Symantec Antivirus
Symantec Client Proxy
Symantec Client Security