SB2019112112 - Security Bypass in Symantec Norton App Lock



SB2019112112 - Security Bypass in Symantec Norton App Lock

Published: November 21, 2019

Security Bulletin ID SB2019112112
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-18373)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a security-bypass vulnerability. An administrator with physical access can circumvent the app to prevent it from locking other apps on the device and gain access to the target system.


Remediation

Install update from vendor's website.