Advertisement






Norton DLL faking via 'SuiteOwners' protection bypass Vulnerability

CVE Category Price Severity
CVE-2021-12345 CWE-119 $5000 High
Author Risk Exploitation Type Date
Security Researcher Critical Remote 2006-08-25
CPE PURL
cpe:cpe:/a:norton:antivirus pkg:pkg:exp:exploitalert/norton-dll-faking-via-suiteowners-protection-bypass-vulnerability
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006080137

Below is a copy:

Hello,

I would like to inform you about a vulnerability in the Norton Personal
Firewall component found by Matousec - Transparent security.

Description:

Norton protects its own registry keys against actions of other applications. This protection can be bypassed for 
registry key 'HKLMSOFTWARESymantecCCPDSuiteOwners' using API functions RegSaveKey and RegRestoreKey. This registry 
key is also used to store some important information such us names of libraries, for example 'NISProd.dll'. Using 
RegSaveKey and RegRestoreKey a malicious application can modify values in 'SuiteOwners' such that Norton loads fake 
library into its own processes. A malicious code in the fake library can manipulate any Norton component and thus bypass 
every security protection of Norton.

Vulnerable software:

* Norton Personal Firewall 2006 version 9.1.0.33
     * probably all versions of Norton Personal Firewall 2006 and Norton Internet Security 2006
     * possibly older versions of Norton Personal Firewall and Norton Internet Security

More details and proof of concept is available
here http://www.matousec.com/info/advisories/Norton-DLL-faking-via-SuiteOwner
s-protection-bypass.php

Regards,

-- 
David Matousek

Founder and Chief Representative of Matousec - Transparent security
http://www.matousec.com/

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum