CVE-2016-6592 Information
Feb 14, 2021
cve
Description
A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that when placed on the target user’s system will cause the Norton Download Manager component to load the remote user’s DLL instead of the intended DLL and execute arbitrary code when the Norton Download Manager component is run by the target user.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/94695 http://www.securityfocus.com/bid/95444 http://www.securitytracker.com/id/1037622 http://www.securitytracker.com/id/1037623 http://www.securitytracker.com/id/1037624 https://support.symantec.com/us/en/article.SYMSA1394.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: