The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used...
Vulnerability Description
The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors related to content on a web site, and place Internet Explorer into a "defunct state" in which remote attackers can execute arbitrary code in addition to other Symantec ActiveX controls, regardless of whether they are marked safe for scripting. NOTE: this CVE was inadvertently used for an E-mail Auto-Protect issue, but that issue has been assigned CVE-2007-3771.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3456
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.symantec.com/avcenter/security/Content/2007.05.09.html
- http://www.vupen.com/english/advisories/2007/1751
- http://www.securityfocus.com/bid/23822
- http://secunia.com/advisories/25172
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=529
- http://osvdb.org/35075
- http://www.securitytracker.com/id?1018031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34200
More from symantec
View All →Affected Vendor
symantec
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.