Norton Anti-Virus SYMTDI.SYS Driver Lets Local Users Gain Elevated Privileges
|
SecurityTracker Alert ID: 1018372 |
SecurityTracker URL: http://securitytracker.com/id/1018372
|
CVE Reference:
CVE-2007-3673
(Links to External Site)
|
Date: Jul 11 2007
|
Impact:
Root access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2005, 2006
|
Description:
A vulnerability was reported in Norton Anti-Virus. A local user can obtain elevated privileges on the target system.
A local user can send a specially crafted IRP to a certain IOCTL handler in the SYMTDI.SYS driver to overwrite memory with kernel level privileges.
Norton AntiSpam, Norton Internet Security, Norton Personal Firewall, Norton System Works, Symantec AntiVirus Corporate Edition, and Symantec Client Security are also affected.
Symantec credits iDefense with reporting this vulnerability.
|
Impact:
A local user can obtain elevated privileges on the target system.
|
Solution:
The vendor has issued a fix, available via LiveUpdate.
The Symantec advisory is available at:
http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11d.html
|
Vendor URL: securityresponse.symantec.com/avcenter/security/Content/2007.07.11d.html (Links to External Site)
|
Cause:
Access control error, Input validation error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|