vendor:
Symantec Antivirus
by:
Project Zero
7.5
CVSS
HIGH
Memory corruption
119
CWE
Product Name: Symantec Antivirus
Affected Version From: Version 4.1.4
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows, Linux, Mac
Vulnerability in Symantec Antivirus Decomposer
The Symantec Antivirus scan engine's Decomposer component, responsible for unpacking various archive formats, is based on an outdated version (4.1.4) of the open-source unrar package. This version has multiple critical memory corruption bugs that have been resolved in the current version (5.3.11). Publicly known vulnerabilities can result in remote code execution as NT AUTHORITYSYSTEM on Windows and root on Linux and Mac. This vulnerability affects Norton Antivirus, Symantec Endpoint Protection, and Symantec Scan Engine, as well as other Symantec products using the core Symantec scan engine.
Mitigation:
Update the Symantec Antivirus scan engine to the latest version of the unrar package (5.3.11) or implement mitigations to protect against memory corruption vulnerabilities.