Lucene search

K
cvelistSymantecCVELIST:CVE-2017-13676
HistorySep 27, 2017 - 3:00 p.m.

CVE-2017-13676

2017-09-2715:00:00
symantec
www.cve.org
3

EPSS

0

Percentile

12.6%

Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a specific search path to locate the DLL. The vulnerability can be exploited by a simple file write (or potentially an over-write) which results in a foreign DLL running under the context of the application. A Norton Remove & Reinstall update, version 4.4.0.58, has been released which addresses the aforementioned vulnerability.

CNA Affected

[
  {
    "product": "Norton Remove & Reinstall",
    "vendor": "Symantec Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "Prior to 4.4.0.58"
      }
    ]
  }
]

EPSS

0

Percentile

12.6%

Related for CVELIST:CVE-2017-13676