DLL Preloading Vulnerability in Norton Remove & Reinstall by Symantec
CVE-2017-13676
7HIGH
What is CVE-2017-13676?
Norton Remove & Reinstall has a DLL preloading vulnerability that could allow an attacker to execute a malicious DLL. This occurs when the application fails to adequately validate the source of the DLL it uses, enabling an attacker to place a harmful DLL in the application's directory. When the application seeks to load the DLL, it inadvertently loads the malicious version instead. To mitigate this vulnerability, users are urged to update to Norton Remove & Reinstall version 4.4.0.58 or later, which fixes the issue.
Affected Version(s)
Norton Remove & Reinstall Prior to 4.4.0.58
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved