Symantec scrambles to patch severe holes in 26 products

By

"As bad as it gets" flaws in enterprise, consumer security offerings.

Symantec enterprise and Norton security product users are being urged to patch their applications immediately after multiple dangerous vulnerabilities were discovered.

Symantec scrambles to patch severe holes in 26 products

The security firm has advised that 17 enterprise security products and nine Norton consumer offerings are affected.

Google Project Zero researcher Tavis Ormandy discovered the flaws. The most serious is that the products unpack compressed executables in the operating system kernel to analyse them for malicious code.

He said this dangerous practice means the vulnerability can be exploited by simply sending a link or an email - users don't need to do anything to activate an attack.

It is also possible to exploit the decomposer library in the core scan engine of Symantec's antivirus products and Endpoint Enterprise Protection applications to remotely execute code at the Windows system level, Ormandy found.

"These vulnerabilities are as bad as it gets. They don’t require any user interaction, they affect the default configuration, and the software runs at the highest privilege levels possible," he wrote.

"In certain cases on Windows, vulnerable code is even loaded into the kernel, resulting in remote kernel memory corruption."

Ormandy found eight serious vulnerabilities in Symantec's security products, potentially affecting millions of enterprise users and consumers who have not patched their systems.

The flaws include buffer and integer overflow vulnerabilities, as well as exploitable memory corruption bugs that could lead to local application denial of service and remote code execution, Symantec warned.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Greater Western Water's billing system data issues laid bare

Greater Western Water's billing system data issues laid bare

Accenture to buy Australian cyber security firm CyberCX

Accenture to buy Australian cyber security firm CyberCX

TPG Telecom reveals iiNet order management system breached

TPG Telecom reveals iiNet order management system breached

Log In

  |  Forgot your password?