This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Symantec AV Vuln per eEye - Severity: High

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://news.yahoo.com/s/ap/20060525/ap_on_…/antivirus_flaw
May 25, 2006
"WASHINGTON - Symantec Corp.'s leading antivirus software, which protects some of the world's largest corporations and U.S. government agencies, suffers from a flaw that lets hackers seize control of computers to steal sensitive data, delete files or implant malicious programs, researchers said Thursday. Symantec said it was investigating the issue but could not immediately corroborate the vulnerability. If confirmed, the threat to computer users would be severe because the security software is so widely used, and because no action is required by victims using the latest versions of Norton Antivirus to suffer a crippling attack over the Internet. Symantec has boasted its antivirus products are installed on more than 200 million computers. A spokesman, Mike Bradshaw, said the company was examining the reported flaw but described it as "so new that we don't have any details." Researchers from eEye Digital Security Inc. of Aliso Viejo, Calif., discovered the vulnerability and provided evidence to Symantec engineers this week, said eEye's chief hacking officer, Marc Maiffret… a note about the company's discovery on its Web site but pledged not to reveal details publicly that would help hackers attack Internet users until after Symantec repairs its antivirus software…"

- http://www.eeye.com/html/research/upcoming/20060524.html
Date Reported: May 24, 2006
Vendor: Symantec
Description:
A remotely exploitable vulnerability exists within the Symantec Antivirus program. This flaw does not require any end user interaction for exploitation and can compromise affected systems, allowing for the execution of malicious code with SYSTEM level access.
Severity: High (Remote Code Execution)
Remote Code Execution: Yes
Software Affected:
- Symantec Antivirus 10.x
- Symantec Client Security 3.x
(Other Symantec Antivirus products are also potentially affected, waiting for vendor list) …"

:ph34r:
FYI…

- http://securityresponse.symantec.com/avcen…2006.05.25.html
Symantec Client Security and Symantec AntiVirus Elevation of Privilege
Revision History
May 26, 2006 - Updated Products Affected section and other details
Impact: High…
Products Affected
Product Version Build Solution
Symantec Client Security 3.1 All Pending
Symantec Antivirus Corp 10.1 All Pending…
"…Mitigation
Symantec Security Response has released IDS signatures to detect attempts to exploit this issue.
Symantec Network Security Appliance 7100 signatures, SU 46, are available via LiveUpdate.
Symantec Gateway Security 3.0 signatures, SU 19, are available via LiveUpdate.
Symantec Client Security 2.0 and 3.0 signatures, SU 22, are available for update via LiveUpdate.

To help reduce the risks associated with this vulnerability Symantec recommends the following best practices:
- As a mitigation strategy, Symantec Security Response has also made available IPS signatures for Symantec Client Security to protect against exploits of the described vulnerability. Symantec recommends customers immediately apply the latest Security Update to protect against potential related attacks.
- IPS Security Updates are available via LiveUpdate.

As best practice, Symantec strongly recommends the following:
* Restrict access to administration or management systems to privileged users only, with additional restricted access to the physical host system(s) if possible.
* Keep all operating systems and applications updated with the latest vendor patches.
* Follow a multi-layered approach to security. Run both firewall and antivirus applications, at a minimum to provide multiple points of detection and protection to both inbound and outbound threats.
* Be cautious visiting unknown or untrusted websites or following unknown URL links.
* Do not open attachments or executables from unknown sources or that you didn't request or were unaware of. Always err on the side of caution. Even if the sender is known, the source address may be spoofed…"

:huh:
FYI…

- http://www.crn.com/showArticle.jhtml?artic…bleArticle=true
6:01 PM EDT Fri. May. 26, 2006
"…One security vendor executive who asked not to be named was baffled by Symantec's decision to release IPS signatures because hackers could reverse engineer the signatures and have a blueprint of the vulnerability, the source said. "As an advocate for responsible disclosure, we are scratching our heads [in disbelief]," the source said. The Symantec vulnerability is another example of why enterprises need to look at security as a layered approach…"

:huh: :oops:
FYI…

- http://securityresponse.symantec.com/avcen…2006.05.25.html
May 27, 2006 - Updated Products Affected section with update info…

- http://www.symantec.com/techsupp/enterpris…ct_updates.html

EDIT/ADD: (per e-mail from Symantec)

Symantec Client Security (SCS) 3.1 Point Patch 1
- http://www.symantec.com/techsupp/enterpris…_3.1/files.html
"…Symantec encourages you to immediately download and install Symantec Client Security Point Patch 1…"

Symantec AntiVirus CE 10.1 Point Patch 1
- http://www.symantec.com/techsupp/enterpris…10.1/files.html
"…Symantec encourages you to immediately download and install Symantec AntiVirus CE Point Patch 1…"

:ph34r:
FYI…

Symantec AV Vulnerability Latest
- http://isc.sans.org/diary.php?storyid=1368
Last Updated: 2006-05-29 14:52:28 UTC
"Symantec has updated their advisory*…
They confirm that the following versions are affected and patches are available:
Symantec Client Security-
3.0 Builds 3.0.2.2010 and 3.0.2.2020
3.1 Builds 3.1.0.394 and 3.1.0.400
Symantec Antivirus Corporate Edition-
10.0 Builds 10.0.2.2010 and 10.0.2.2020
10.1 Builds 10.1.0.394 and 10.1.0.400
Some have reported that the patching process is not trivial, and can be difficult to roll out in some environments. At this time, there have been no reports of proof-of-concept-code or exploit code other than that held privately by eEye. We have not received any reports of exploitation in the wild."

* http://www.symantec.com/avcenter/security/…2006.05.25.html
Last modified on: Saturday, 27-May-06 21:24:29

:mellow:
FYI…

More on Symantec vulnerabilities
- http://isc.sans.org/diary.php?storyid=1372
Last Updated: 2006-05-31 01:21:02 UTC
"The latest patches from Symantec are causing quite a bit of confusion…
*ALL* versions of 10.0.x and 10.1.x of Symantec Antivirus Corporate Edition and 3.0.x and 3.1.x of Symantec Client Security seem to be vulnerable.
Symantec Antivirus Corporate Edition version 8.x and 9.x seem to be ok.
Symantec released 4 patches for each product ( http://www.symantec.com/avcenter/security/…2006.05.25.html ):

Symantec Antivirus Corporate Edition
10.1.0.394 -> 10.1.0.396 (there's a typo here on their web, it's not version 3)
10.1.0.400 -> 10.1.0.401
10.0.2.2010 -> 10.0.2.2011
10.0.2.2020 -> 10.0.2.2021
Symantec Client Security
3.1.0.394 -> 3.1.0.396
3.1.0.400 -> 3.1.0.401
3.0.2.2010 -> 3.0.2.2011
3.0.2.2020 -> 3.0.2.2021

Now, if you are running *ANY* other version that is affected, you will have to first upgrade to one of the versions that have the patch out and then install the patch. I hope this will clear the confusion.
There seem to be some mitigations to the problem though. As eEye stated, this is a remotely exploitable vulnerability. Symantec Antivirus Corporate Edition, when in managed mode, will have the service Rtvscan.exe listening on TCP port 2967. In case that your host based firewall is configured to block access to this port (effectively meaning that you can't manage the client from the centralized server, at least not until the client connects to it) you should be ok.
On our test machine, the unmanaged installation of Symantec Antivirus Corporate Edition didn't have any listeners so it looks like it's safe, at least from a remote exploit over the network (patch in any case!). If we get more information we'll update the diary…"

:huh: