Symantec patched the vulnerability in ESM products
Symantec has patched a flaw in its enterprise security management tool - Enterprise Security Manager (ESM) has allowed hackers to control affected computers.
Symantec's warning states that all ESM versions (except version 6.5.3) are affected by the remote code execution vulnerability. The vulnerability arises because the remote upgrade interface of the ESM agent does not correctly identify the source of the remote upgrade queries. Hackers can take advantage of this flaw to spread malware through a specially crafted upgrade query.
ESM's automatic and manual upgrades are available at Symantec's website. Officials said they have yet to receive any reports of exploiting the vulnerability.
Danish security firm Secunia once classified the vulnerability in ESM as "moderate", while the French Security Response Group (FSIRT) ranked the vulnerability at "high risk" level by potential hackers. Remote attack.
- AOL patched the image search vulnerability
- Symantec patched vulnerabilities in antivirus software
- Yahoo patched the vulnerability in Yahoo Mail
- Yahoo Messenger vulnerability has not been patched yet
- Symantec launches security products
- Symantec patched the flaw in Norton Internet Security
- Symantec patched up the Norton product suite
- Symantec patched the flaw in Backup Exec application
- McAfee, Symantec patched antivirus software
- Symantec introduced the new 'Terminal Security Solution'
- Code to exploit VML vulnerability
- Symantec tested 2008 security products