Norton Anti-Virus Corporate Edition Help Menu Allows Local Users to Execute Code With Local System Privileges
|
|
SecurityTracker Alert ID: 1005476 |
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Oct 24 2002
|
Impact: Execution of arbitrary code via local system, Root access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 7.60.962
|
Description: A vulnerability was reported in Symantec's Norton Anti-Virus Corporate Edition. A local user can gain System level privileges.
It is reported that a local user can execute 'winhlp32' in the Local System context. Norton Anti-Virus apparently adds a "Scan
for Viruses..." menu item to the Internet Explorer context menu and also provides a "Help" button, both of which allow the local
user to start winhlp32 in the Local System context. This allows the local user to execute code with System level privileges.
ERRor
<error at pochtamt.ru> of Domain HELL Team is credited with discovery.
|
Impact: A local user can execute arbitrary code with System level privileges.
|
Solution: The vendor has reportedly released fixed versions (7.5.1 Build 62 and later; 7.6.1 Build 35a and later).
|
Vendor URL: www.symantec.com/ (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Windows (Any)
|
Reported By: 3APA3A <3APA3A@SECURITY.NNOV.RU>
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 24 Oct 2002 14:39:59 +0400
From: 3APA3A <3APA3A@SECURITY.NNOV.RU>
Subject: DH team: Norton Antivirus Corporate Edition Privilege Escalation
|
Dear Bugtraq,
Product: Norton Antivirus Corporate Edition (Final 7.60.962)
Vendor: Symantec
Type: Local
Risk: High (system privileges)
Discovered: ERRor <error@pochtamt.ru> of Domain HELL Team
Description:
Norton Antivirus allows to run winhlp32 in context of local system.
Details:
Norton Antivirus adds "Scan for Viruses..." item to Explorer's context
menu. Application launched if this item is selected has local system
context. Application has "Help" button which allows to start winhlp32
in context of Local System. winhlp32 allows user to execute code with
credentials of this application.
Vendor:
According to Symantec reply on the moment this problem was reported to
Symantec fix was ready and tested:
This vulnerability has been eliminated in current versions of Symantec
Norton AntiVirus Corporate Edition, version 7.5.1 Build 62 and later
as well as version 7.6.1 Build 35a and later that are available for
download.
Credits:
This issue was discovered by ERRor of Domain Hell Team.
--
http://www.security.nnov.ru
/\_/\
{ , . } |\
+--oQQo->{ ^ }<-----+ \
| ZARAZA U 3APA3A }
+-------------o66o--+ /
|/
You know my name - look up my number (The Beatles)
|
|