Lucene search

K
jvnJapan Vulnerability NotesJVN:40667528
HistoryFeb 10, 2017 - 12:00 a.m.

JVN#40667528: Norton Download Manager may insecurely load Dynamic Link Libraries

2017-02-1000:00:00
Japan Vulnerability Notes
jvn.jp
32

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.021

Percentile

89.3%

Norton Download Manager provided by Symantec Japan, Inc. contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries.

Impact

Arbitrary code may be executed with the privileges of the user running the application.

Solution

Use the latest Norton Download Manager
Use the latest Norton Download Manager according to the information provided by the developer.

The developer states the following in the advisory :

  • Norton Download Manager is not updated through Liveupdate
  • Delete any previously downloaded version of Norton Download Manager
  • Download the updated version of Norton Download Manager associated with their Norton security product

Products Affected

  • Norton Download Manager 5.6 and earlier

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.021

Percentile

89.3%

Related for JVN:40667528