Serious security flaw discovered in the application

Aug 10, 2007 19:21 GMT  ·  By

Symantec is the owner of Norton Antivirus, a famous antivirus solution among numerous Internet users. But in the same time, Symantec is also the creator of one of the most vulnerable security solutions because Norton Antivirus is continuously included into security notifications that reveal more or less critical flaws. Today, it's just an example. Security company Secunia discovered two vulnerabilities in several Symantec products, including Norton Antivirus 2006 that can allow an attacker compromise an affected system. The other vulnerable solutions are Norton Internet Security 2006 and 2006 and Norton SystemWorks 2006.

"Secunia Research has discovered two vulnerabilities in various Symantec products, which can be exploited by malicious people to compromise a user's system. The vulnerabilities are caused due to errors in the AxSysListView32 and AxSysListView32OAA ActiveX controls (NavComUI.dll) when handling the "AnomalyList" and "Anomaly" properties respectively as they take a VARIANT* as argument. Successful exploitation allows execution of arbitrary code," Secunia noted in the notification.

Symantec already confirmed the security holes and rolled out a patch to fix them that is currently distributed through the LiveUpdate feature implemented into all the company's products. As you know, Symantec's security tools periodically updates the database and the virus definitions so if you're one of those vulnerable to attacks, your product was probably already patched.

Symantec is famous for its security solutions and Norton Antivirus, the top product developed by the company, is currently installed on millions of computers in the entire world. But this doesn't necessarily mean that Norton Antivirus is also efficient. Back in June, Symantec received a serious hit even from its product after the antivirus incorrectly flagged some vital Windows files as dangerous and damaged the operating system. As a result, Symantec was force to offer some free licenses for its applications just as a compensation for the affected consumers.