Remote Malware Detection Bypass in Symantec AntiVirus Due to HTML Document Vulnerability
CVE-2008-5543

Currently unrated

Key Information:

Vendor
Symantec
Status
Vendor
CVE Published:
12 December 2008

Summary

Symantec AntiVirus version 10 is susceptible to a significant vulnerability that allows remote attackers to circumvent malware detection when Internet Explorer 6 or 7 is employed. This can be achieved by manipulating an HTML document to include an MZ header (commonly recognized as 'EXE info') at the beginning. Attackers can further obscure their malicious intent by altering the file's extension to either omit it completely, append a .txt, or use a .jpg extension, effectively masking potentially harmful content as benign. This tactic enables the execution of malware exploits without detection, posing serious risks to users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.