PT-2012-1302 · Microsoft+1 · Help/Support Center+1
Published
2012-08-22
·
Updated
2012-08-22
·
CVE-2010-3497
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Symantec Norton AntiVirus version 2011
Description
The issue arises from improper interaction with the Microsoft Help and Support Center's processing of hcp:// URLs, allowing remote attackers to execute arbitrary code. This occurs even when the malware is correctly detected, but the detection happens too late to prevent code execution.
Recommendations
For Symantec Norton AntiVirus version 2011, consider restricting access to hcp:// URLs in the Microsoft Help and Support Center as a temporary mitigation measure until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Help/Support Center
Symantec Norton Antivirus