Vulnerability Name: | CVE-2016-6592 (CCN-120905) | ||||||||||||
Assigned: | 2016-08-03 | ||||||||||||
Published: | 2017-01-17 | ||||||||||||
Updated: | 2020-01-21 | ||||||||||||
Summary: | A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Manager component to load the remote user's DLL instead of the intended DLL and execute arbitrary code when the Norton Download Manager component is run by the target user. | ||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.0 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-427 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-6592 Source: CCN Type: JVN#40667528 Norton Download Manager may insecurely load Dynamic Link Libraries Source: MISC Type: Third Party Advisory, VDB Entry http://www.securityfocus.com/bid/94695 Source: CCN Type: BID-95444 Symantec Norton Download Manager CVE-2016-6592 DLL Loading Remote Code Execution Vulnerability Source: MISC Type: Third Party Advisory, VDB Entry http://www.securityfocus.com/bid/95444 Source: MISC Type: Third Party Advisory, VDB Entry http://www.securitytracker.com/id/1037622 Source: MISC Type: Third Party Advisory, VDB Entry http://www.securitytracker.com/id/1037623 Source: MISC Type: Third Party Advisory, VDB Entry http://www.securitytracker.com/id/1037624 Source: XF Type: UNKNOWN symantec-cve20166592-code-exec(120905) Source: CONFIRM Type: Vendor Advisory https://support.symantec.com/us/en/article.SYMSA1394.html Source: CCN Type: Symantec Security Advisory SYM17-001 Norton Download Manager DLL Loading | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |