CVE-2006-3456

Symantec Norton AntiVirus, Internet Security, and System Works - Remote Code Execution via NAVOPTS.DLL ActiveX Control

Title source: llm
STIX 2.1

Description

The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors related to content on a web site, and place Internet Explorer into a "defunct state" in which remote attackers can execute arbitrary code in addition to other Symantec ActiveX controls, regardless of whether they are marked safe for scripting. NOTE: this CVE was inadvertently used for an E-mail Auto-Protect issue, but that issue has been assigned CVE-2007-3771.

References (8)

Core 8
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1751
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23822
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25172
Vendor Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=529
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/35075
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018031
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34200

Scores

EPSS 0.0823
EPSS Percentile 92.3%

Details

CWE
CWE-94
Status published
Products (6)
symantec/norton_antivirus 2005
symantec/norton_antivirus 2006
symantec/norton_internet_security 2005
symantec/norton_internet_security 2006
symantec/norton_system_works 2005
symantec/norton_system_works 2006
Published May 11, 2007
Tracked Since Feb 18, 2026