Critical hole in Norton AntiVirus and Internet Security
Summary
In 2007 Symantec reported critical holes in Norton AntiVirus 2006, Norton Internet Security and SystemWorks through which a prepared website could take over a Windows PC. The cause was two ActiveX controls in NAVCOMUI.DLL that processed certain objects incorrectly. The updates were already being distributed via LiveUpdate, and the enterprise products were not affected.
Ideas
- Security software brings its own components, which are themselves vulnerable.
- An ActiveX control made the antivirus software reachable from the browser.
- Automatic updates protected users before many of them learned of the hole.
Insights
- Every additional piece of software, including protective software, enlarges the attack surface.
- With widely used software, automatic updates are the most effective protection.
Facts
- The faulty controls were called AxSysListView32 and AxSysListView32OAA.
- Anyone who had disabled LiveUpdate had to trigger the update manually.
References
Critique
- The bugs are only described as “not specified in detail”; independent analyses are missing.
Recommendations
- Let security software update automatically and check that it actually does so.
- Disable browser interfaces of desktop software that you do not need.
Links to the original source and the Web Archive open in a new tab.