Google Researcher Highlights Flaws in Dozens of Norton, Symantec Products

Advertisement
By Shekhar Thakran | Updated: 30 June 2016 17:17 IST
Highlights
  • Symantec fixed the issues informed by Ormandy and asked users to update
  • Issues could have allowed hackers to control OS without user interaction
  • Symantec uses the same core engine across their entire product line
Google Project Zero member and security researcher Tavis Ormandy published a blog on Wednesday detailing major security flaws found in nearly 25 of Norton and Symantec's products being sold to both enterprises and customers.

Ormandy said multiple security flaws were found, including "wormable remote code execution flaws." On his Google Project Zero blog post, Ormandy said, "These vulnerabilities are as bad as it gets. They don't require any user interaction, they affect the default configuration, and the software runs at the highest privilege levels possible. In certain cases on Windows, vulnerable code is even loaded into the kernel, resulting in remote kernel memory corruption."

Further explaining, Ormandy said the vulnerabilities could allow hackers to corrupt a computer's memory as well as gain control over its operating system without the user even opening a malware-wrapped mail or a dangerous link. "Because Symantec uses a filter driver to intercept all system I/O, just emailing a file to a victim or sending them a link to an exploit is enough to trigger it - the victim does not need to open the file or interact with it in anyway," he added.

"As Symantec use the same core engine across their entire product line, all Symantec and Norton branded antivirus products are affected by these vulnerabilities," Ormandy said in his blog, referring to the Symantec AntiVirus Decomposer engine.

Symantec, however, has fixed the issues with its products after they were informed about the flaws by Ormandy - who published the blog post a day after the fixes were released. While most products will be updated automatically, several enterprise products will require administrators to effect fixes themselves. Symantec has issued a warning to its customers and explained how they can update their products.

In its security response post, Symantec highlights the affected products and the solution implemented. In the post, the company said, "Symantec is aware of buffer overflow and memory corruption findings in the AntiVirus Decomposer engine used in various configurations by multiple Symantec products." The post added, "Symantec has verified these issues and addressed them in product updates as identified in the solution portion of the affected products matrix above. We have also added additional checks to our Secure Development LifeCycle to mitigate similar issues in future... Symantec is not aware of these vulnerabilities being exploited in the wild."
 
Google Project Zero team is a group of security analysts that aims to improve overall security of computers and informs the manufacturer of the products about their flaws before releasing it to public. The team usually waits for the patch to come out before releasing the details about the flaws. However, if a patch is not released for 90 days post intimation (plus a two-week grace period), the team releases the details to the public. In this case, Ormandy helped the company create fixes by making a "100 percent reliable exploit" for them.

The release is likely to hurt the reputation of Symantec and its Norton Antivirus brand in particular. Ormandy in his blog post also criticises the development process at Symantec, specifically its vulnerability management, which is meant to monitor updates released for third party software. "Symantec dropped the ball here. A quick look at the decomposer library shipped by Symantec showed that they were using code derived from open source libraries like libmspack and unrarsrc, but hadn't updated them in at least 7 years... Dozens of public vulnerabilities in these libraries affected Symantec, some with public exploits. We sent Symantec some examples, and they verified they had fallen behind on releases."

On June 13, Symantec announced its plans to buy privately held cyber-security company Blue Coat for $4.65 billion (roughly Rs. 31,165 crores) in a cash deal that to enhance Symantec's enterprise security business.

The announcement came as a surprise to the industry as the amount for the deal was more than Symantec's revenue for the entire last fiscal year i.e. $3.6 billion (Rs. 24,336 crores).

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. CMF Headphone Pro With Up to 100 Hours of Battery Life Launched: See Price
  2. Sandisk Launches Creator Series Storage Devices in India: Price, Details
  3. Flipkart Big Billion Days Sale: Top Deals Before It Ends on This Date
  4. YouTube Premium Lite is Now Available in India at This Price
  5. Sony Finally Launches Its WH-1000XM6 Wireless Headphones in India: See Price
  6. Five Reasons Why Samsung Galaxy S24 Ultra is The Biggest Deal of 2025
  7. Vivo Announces Android 16 Preview Program for Vivo and iQOO Smartphones
  8. OnePlus Reveals 'Sand Dune' Colourway of OnePlus 15 With Minimal Bezels
  9. Realme 15 Pro 5G Game of Thrones Edition to Soon Launch in India
  10. Samsung Galaxy S26 Ultra Could Feature This Chipset and Camera
  1. Apple Releases iOS 26.0.1 Update With Fixes for Bluetooth, Camera, and Cellular Issues on iPhone 17 and iPhone Air
  2. WhatsApp Announces Support for Sharing Live Photos, Meta AI-Powered Chat Themes, New Sticker Packs, and More
  3. Physicists Identify Loophole in Heisenberg’s Uncertainty Principle While Preserving Its Validity
  4. SpaceX’s Falcon 9 Lifts Off Successfully From Vandenberg Space Force Base
  5. NASA Faces Uncertainty Over Space Plane Missions to ISS Before Its Deorbit
  6. SpaceX Falcon 9 Deploys 28 Next-Generation Starlink V2 Mini Satellites
  7. How To Train Your Dragon OTT Release Date: When and Where to Watch This Live Action Movie Online?
  8. War 2 OTT Release Date: When and Where to Watch To Watch Hrithik Roshan Starrer Action Movie
  9. Twisted Metal Season 2 Now Streaming on Sony LIV: Know Everything about Plot, Cast, and More
  10. Battlefield Maker Electronic Arts to Go Private in Record $55 Billion Leveraged Buyout
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.