bk99.de entertain the web since 1997

Critical hole in Norton AntiVirus and Internet Security

Summary

In 2007 Symantec reported critical holes in Norton AntiVirus 2006, Norton Internet Security and SystemWorks through which a prepared website could take over a Windows PC. The cause was two ActiveX controls in NAVCOMUI.DLL that processed certain objects incorrectly. The updates were already being distributed via LiveUpdate, and the enterprise products were not affected.

Ideas

  • Security software brings its own components, which are themselves vulnerable.
  • An ActiveX control made the antivirus software reachable from the browser.
  • Automatic updates protected users before many of them learned of the hole.

Insights

  • Every additional piece of software, including protective software, enlarges the attack surface.
  • With widely used software, automatic updates are the most effective protection.

Facts

  • The faulty controls were called AxSysListView32 and AxSysListView32OAA.
  • Anyone who had disabled LiveUpdate had to trigger the update manually.

References

Critique

  • The bugs are only described as “not specified in detail”; independent analyses are missing.

Recommendations

  • Let security software update automatically and check that it actually does so.
  • Disable browser interfaces of desktop software that you do not need.

Read the original article

Search the Web Archive