VulnerabilityModified
CVE-2001-1125
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.
CRITICAL 9.8EPSS 2.47%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.47% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-494
- Affected
- symantec/liveupdate
- Source
- cve@mitre.org
References
- http://www.sarc.com/avcenter/security/Content/2001.10.05.htmlBroken Link
- http://www.securityfocus.com/archive/1/218717Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/3403Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7235Third Party Advisory, VDB Entry
- http://www.sarc.com/avcenter/security/Content/2001.10.05.htmlBroken Link
- http://www.securityfocus.com/archive/1/218717Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/3403Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7235Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.