Remote Malware Detection Bypass in Symantec AntiVirus Due to HTML Document Vulnerability
CVE-2008-5543
Currently unrated
Summary
Symantec AntiVirus version 10 is susceptible to a significant vulnerability that allows remote attackers to circumvent malware detection when Internet Explorer 6 or 7 is employed. This can be achieved by manipulating an HTML document to include an MZ header (commonly recognized as 'EXE info') at the beginning. Attackers can further obscure their malicious intent by altering the file's extension to either omit it completely, append a .txt, or use a .jpg extension, effectively masking potentially harmful content as benign. This tactic enables the execution of malware exploits without detection, posing serious risks to users.
References
Timeline
Vulnerability published
Vulnerability Reserved