Google finds severe vulnerabilities in 25 Norton and Symantec products

Google’s Project Zeo has found numerous severe vulnerabilities in 25 Norton and Symantec products which could be used to exploit a ‘protected’ system.

A common complaint amongst users of Symantec’s Norton Anti-Virus software is that they often feel they’ve encumbered their computer with a virus, rather than release that burden altogether.
Now, Google’s Project Zero team – which searches for code flaws and gives them 90 days to fix them – has identified numerous threats and vulnerabilities within 25 of Symantec’s products.
Read: Top 5: Free Android Antivirus Apps
Project Zero researcher Tavis Ormandy identified the problems are ‘as bad as it gets’, citing that “Just emailing a file to a victim or sending them a link to an exploit is enough to trigger it — the victim does not need to open the file or interact with it in any way.”
Ormandy cited that the danger of the errors was the result of severe incompetence; in one instance, Ormandy found a buffer overflow in Symantec’s “unpacker”; meaning that the program had the capability to violate and write over memory locations. Of the error, Ormandy wrote that “Because no interaction is necessary to exploit it, this is a wormable vulnerability with potentially devastating consequences… an attacker could easily compromise an entire enterprise fleet.”
Ormandy further revealed that he discovered that Symantec had used open source libraries to construct its vulnerability management system, which checks for published flaws. While that on its own is fine, the fact that the company had failed to update them in 7 years is highly worrying.
To its credit, however, the firm published updates for the errors before Ormandy could conclude his report.
The news is a disturbing revelation for consumers, who have been advised to update to the latest version of any Symantec software package immediately.
Read: Kaspersky AV “œmost effective“ Antivirus Product in Independent Study
What are your thoughts on the flaws found within Symantec’s software packages? Be sure to let us know your thoughts in the comments below!
Follow Bryan Smith on Twitter: @bryansmithSA