PT-2018-16829 · Symantec · Norton Power Eraser+1

Published

2018-08-22

·

Updated

2018-11-14

·

CVE-2018-5238

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Norton Power Eraser versions prior to 5.3.0.24 SymDiag versions prior to 2.1.242
Description The issue is related to a DLL Preloading vulnerability, which occurs when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. This can be exploited by a simple file write, resulting in a foreign DLL running under the context of the application.
Recommendations For Norton Power Eraser versions prior to 5.3.0.24, update to version 5.3.0.24 or later. For SymDiag versions prior to 2.1.242, update to version 2.1.242 or later.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5238

Affected Products

Norton Power Eraser
Symdiag