Home > Security News > Symantec AntiVirus Corporate Edition vulnerable to flaw
Security News:
EMAIL THIS

Symantec AntiVirus Corporate Edition vulnerable to flaw

By Bill Brenner, Senior News Writer
26 May 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Attackers could launch malicious code to gain system-level privileges by exploiting a flaw in Symantec AntiVirus Corporate Edition 10, Aliso Viejo, Calif.-based eEye Digital Security Inc. has warned in an advisory.

The company labeled the security hole "high-severity" and Cupertino, Calif.-based Symantec Corp. said it is investigating eEye's findings. Details on the exact nature of the vulnerability were not immediately available.

More on Symantec

Symantec vows to fend off Microsoft

Review: Symantec's integrated security appliance a good fit

Symantec flaw parallels SonyBMG

"This flaw does not require any end-user interaction for exploitation and can compromise affected systems, allowing for the execution of malicious code with system-level access," eEye said in its brief advisory.

In its advisory detailing the AntiVirus Corporate Edition 10 flaw, Symantec said its Norton products "do not contain the code affected by this potential vulnerability, and none of the Norton products are affected by this issue." The company said its product teams are investigating and, if necessary, "we will provide updates for all currently supported products to resolve this issue."

Symantec added that it's not aware of any customers that have been affected by the flaw. "There is no known exploit code currently in the wild that takes advantage of this reported vulnerability," the company said.

For now, Symantec said AntiVirus Corporate Edition customers can mitigate the threat by:

  • Blocking external access at the network boundary, unless external parties require service.
  • Filtering access to the affected computer at the network boundary if global accessibility is not required.
  • Restricting access to only trusted computers and networks.
  • Deploying network intrusion detection systems (IDS) to monitor network traffic for malicious activity.
  • Not accepting or executing files from untrusted or unknown sources.
  • Avoiding the acceptance of or executing files that originate from users of questionable integrity.

    Tags: Security Industry Market Trends, Predictions and ForecastsDatabase Security ManagementSecuring Productivity ApplicationsMalware, Viruses, Trojans and SpywareVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Security Industry Market Trends, Predictions and Forecasts
    M86 buys Web security gateway vendor Finjan
    Information Security Decisions 2009: Presentation downloads
    Bruce Schneier on outsourcing, awareness training
    Marcus Ranum on cyberwarfare, infosec careers
    McAfee survey finds faults in midmarket enterprise security
    Email archiving vendor sues Gartner over Magic Quadrant
    Information Security magazine October issue PDF
    Editor's Desk: Security 7 Winners Chronicle Trends That Shape The Industry
    Information Security magazine Security 7 Award winners
    Security Squad: Privacy gone awry
    Security Industry Market Trends, Predictions and Forecasts Research

    Database Security Management
    What is the best database patch management process?
    Unpatched vulnerability discovered in Microsoft SQL Server
    SQL injection continues to trouble firms, lead to breaches
    Oracle issues quarterly patches, fixes database flaws
    Database monitoring, encryption vital in tight economy, Forrester says
    Oracle to buy Sun Microsystems for $7.4 billion
    Oracle issues 43 updates, fixes serious database flaws
    Imperva assigns security risk levels to databases
    How to create configuration management plans to install DLP
    Information security book excerpts and reviews
    Database Security Management Research

    Securing Productivity Applications
    How to detect software tampering
    Adobe fixes 29 flaws in Acrobat, Reader
    Adobe warns of critical update for Reader, Acrobat 9.1.3
    Why should we place data files on a separate partition than the OS?
    Adobe updates ColdFusion, JRun, Flex
    Serious Adobe Flash flaw being exploited
    Adobe acknowledges serious Flash zero-day vulnerability
    Adobe issues security advisory for Flash zero-day flaw
    When to use the service features of the Metasploit hacking tool
    How to manage patches for Adobe

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    backscatter body scanning  (SearchSecurity.com)
    marketecture  (SearchSecurity.com)
    NCSA  (SearchSecurity.com)
    Palladium  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts