LandzDown Forum

Security => Security Alerts & Briefings => Topic started by: Eric the Red on January 11, 2006, 09:35:08 PM

Title: Symantec Norton Protected Recycle Bin Exposure
Post by: Eric the Red on January 11, 2006, 09:35:08 PM
Symantec have posted details of a potential vulnerability whereby malware could be hidden from scanning. This effects Norton SystemWorks 2005 and 2006. Users are advised to update the software:

QuoteNorton SystemWorks contains a feature called the Norton Protected Recycle Bin, which resides within the Microsoft Windows Recycler directory. The Norton Protected Recycle Bin includes a directory called NProtect, which is hidden from Windows APIs. Files in the directory might not be scanned during scheduled or manual virus scans. This could potentially provide a location for an attacker to hide a malicious file on a computer....

Symantec product engineers have developed and released an update for products affected by this exposure. The update is available through Symantec LiveUpdate by running a manual update. To manually update via Symantec LiveUpdate, users should:

Open Norton SystemWorks
Click on LiveUpdate
Run LiveUpdate until all available Symantec product updates are downloaded and installed
This update will require a system reboot.


Source: http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html (http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html)