Symantec Acknowledges Zero-Day Vulnerability in its AntiVirus Product
By Doug Edelman (05/27/06)
According to an alert issued Thursday by security vendor eEye Digital, Symantec AntiVirus 10.x and Symantec Client Security 3.x have a vulnerability that could be attacked via a worm which required no action on the part of the user to compromise a computer and allow remote access and control.
On Friday, Symantec acknowledged the vulnerability. Their spokesman attempted to minimize concern. "Symantec has not had any reports of any related exploits of this suspected vulnerability. Symantec Product Security is working on providing prompt mitigation solutions for any confirmed issues."
Symantec issued no information on when a patch might be released. They are also being closed-mouthed about the investigation, saying details are being withheld until a patch or update is available. "This is to prevent development of exploits and malicious code while a fix is pending."
Copyright © 2006 by Doug Edelman
(Printer friendly version) Email: Doug Edelman