SB2018061321 - Input validation error in Symantec Norton App Lock



SB2018061321 - Input validation error in Symantec Norton App Lock

Published: June 13, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018061321
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2018-5242)

The vulnerability allows a local privileged user to execute arbitrary code.

Norton App Lock prior to version 1.3.0.329 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access.


Remediation

Install update from vendor's website.