- Mar 24, 2017
- 481
A vulnerability in Symantec endpoint clients remains unpatched months after disclosure, according to security researchers.
A vulnerability in Symantec endpoint clients remains unpatched months after disclosure, according to security researchers.
The zero-day bug affects a kernel driver in two Symantec products, Symantec Encryption Desktop suite version 10.4.1 MP2HF1 (Build 777) and earlier, module PGPwded.sys and Symantec Endpoint Encryption version v11.1.3 MP1 (Build 810) and earlier, module eedDiskEncryptionDriver.sys.
The vulnerability allows an attacker to attain arbitrary hard disk read and write access at sector level, and subsequently infect the target and gain low level persistence (MBR/VBR). They also allow the attacker to execute code in the context of the built-in SYSTEM user account, without requiring a reboot.
Not sure how many of you use those products but I thought that I would share this. Not good to hear about this from a security business.
Last edited: