PT-2018-16826 · Symantec · Norton Utilities

Published

2018-08-22

·

Updated

2020-08-24

·

CVE-2018-5235

CVSS v3.1

6.0

Medium

VectorAV:P/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Norton Utilities versions prior to 16.0.3.44
Description The issue is related to a DLL Preloading vulnerability. This type of vulnerability occurs when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. The application follows a specific search path to locate the DLL, which can be exploited by a simple file write or potentially an over-write, resulting in a foreign DLL running under the context of the application.
Recommendations For versions prior to 16.0.3.44, update to version 16.0.3.44 or later to resolve the issue.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5235

Affected Products

Norton Utilities