PT-2018-16826 · Symantec · Norton Utilities
Published
2018-08-22
·
Updated
2020-08-24
·
CVE-2018-5235
CVSS v3.1
6.0
Medium
| Vector | AV:P/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Norton Utilities versions prior to 16.0.3.44
Description
The issue is related to a DLL Preloading vulnerability. This type of vulnerability occurs when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. The application follows a specific search path to locate the DLL, which can be exploited by a simple file write or potentially an over-write, resulting in a foreign DLL running under the context of the application.
Recommendations
For versions prior to 16.0.3.44, update to version 16.0.3.44 or later to resolve the issue.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Norton Utilities