CVE-2002-1540
The client for Symantec Norton AntiVirus Corporate Edition 7.5.x before 7.5.1 Build 62 and 7.6.x before 7.6.1 Build 35a runs winhlp32 with raised privileges, which allows local users to gain privileges by using certain features of winhlp32.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The client for Symantec Norton AntiVirus Corporate Edition 7.5.x before 7.5.1 Build 62 and 7.6.x before 7.6.1 Build 35a runs winhlp32 with raised privileges, which allows local users to gain privileges by using certain features of winhlp32.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Affected
- symantec/norton antivirus
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0346.html
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0369.html
- http://www.iss.net/security_center/static/10475.phpPatch, Vendor Advisory
- http://www.osvdb.org/6258
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0346.html
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0369.html
- http://www.iss.net/security_center/static/10475.phpPatch, Vendor Advisory
- http://www.osvdb.org/6258
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.