Security restrictions bypass in Symantec Norton App Lock

Published: 2019-01-11 18:50:15
Severity Low
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2018-18363
CVSSv3 5.4 [CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CWE ID CWE-264
Exploitation vector Local
Public exploit N/A
Vulnerable software Norton App Lock
Vulnerable software versions Norton App Lock -
Vendor URL Symantec Corporation

Security Advisory

1) Security restrictions bypass

Description

The vulnerability allows a physical high-privileged attacker to bypass security restrictions on the target system.

The vulnerability exists due to improper privileges and access control. A physical attacker can circumvent the app to prevent it from locking the device and gain device access.

Remediation

Update to version 1.4.0.445.

External links

https://support.symantec.com/en_US/article.SYMSA1473.html

Back to List