Symantec.NavComUI.ActiveX.Control.Remote.Code.Execution

description-logoDescription

This indicates an attempt to exploit a remote Code Execution vulnerability that is present in multiple Symantec products.
The vulnerability is caused by the improper handling of the "AnomalyList" and "Anomaly" properties, by the "AxSysListView32" and "AxSysListView32OAA" ActiveX controls in "NavComUI.dll". It could allow a remote attacker to execute arbitrary code on a vulnerable system.

affected-products-logoAffected Products

Symantec Norton System Works 2006
Symantec Norton Internet Security 2006
Symantec Norton Internet Security 2005 Anti Spyware Edition
Symantec Norton AntiVirus 2006

Impact logoImpact

System compromise: Arbitrary code execution.

recomended-action-logoRecommended Actions

The vendor has released fixes to address these issues, which are available via LiveUpdate in Interactive Mode.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)