Insufficient Integrity Checks in Symantec LiveUpdate
CVE-2001-1125
9.8CRITICAL
Summary
Symantec LiveUpdate versions prior to 1.6 lack essential cryptographic verification for download files. This flaw enables remote attackers to exploit DNS spoofing vulnerabilities, allowing them to deliver malicious payloads that could execute arbitrary code on user systems. Users are at risk of installing unauthorized software updates that could compromise the security and integrity of their systems significantly.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published