First published: Tue Jan 14 2020(Updated: )
A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Manager component to load the remote user's DLL instead of the intended DLL and execute arbitrary code when the Norton Download Manager component is run by the target user.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Norton Download Manager | <5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-6592 is high with a CVSS score of 7.8.
The affected software by CVE-2016-6592 is Symantec Norton Download Manager versions prior to 5.6.
A remote user can exploit CVE-2016-6592 by creating a specially crafted DLL file and placing it on the target user's system, causing the Norton Download Manager component to load the remote user's DLL instead of the intended DLL and executable files.
Yes, there are references available for CVE-2016-6592. You can find them at the following links: [Reference 1](http://www.securityfocus.com/bid/94695), [Reference 2](http://www.securityfocus.com/bid/95444), and [Reference 3](http://www.securitytracker.com/id/1037622).
The Common Weakness Enumeration (CWE) ID associated with CVE-2016-6592 is CWE-427.