PT-2018-16829 · Symantec · Norton Power Eraser+1
Published
2018-08-22
·
Updated
2018-11-14
·
CVE-2018-5238
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Norton Power Eraser versions prior to 5.3.0.24
SymDiag versions prior to 2.1.242
Description
The issue is related to a DLL Preloading vulnerability, which occurs when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. This can be exploited by a simple file write, resulting in a foreign DLL running under the context of the application.
Recommendations
For Norton Power Eraser versions prior to 5.3.0.24, update to version 5.3.0.24 or later.
For SymDiag versions prior to 2.1.242, update to version 2.1.242 or later.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Norton Power Eraser
Symdiag