Symantec Multiple Products Insecure Library Loading Vulnerability
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability has been identified in Symantec Backup Exec System Recovery 2010 and Symantec System Recovery 2011, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to the applications loading libraries (e.g. imapi.dll) via the "Granular Restore Option" and "Recovery Point Browser" directories in an insecure manner. This can be exploited to load an arbitrary library by tricking a user into opening an specially crafted file located on a remote WebDAV or SMB share.
Impact
- Remote Code Execution
System / Technologies affected
- Symantec Backup Exec System Recovery 2010 prior to SP5
- Symantec System Recovery 2011 prior to SP2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to a fixed version.
Vulnerability Identifier
Source
Related Link
Share with