Input validation error in Norton App Lock - CVE-2018-5239

 

Input validation error in Norton App Lock - CVE-2018-5239

Published: July 16, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36899
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5239
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to execute arbitrary code.

Norton App Lock prior to v1.3.0.332 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access.


Affected software

Norton App Lock

How to mitigate CVE-2018-5239

Install update from vendor's website.

Norton App Lock - update to 1.3.0.332

External References

Related Security Bulletins