Executive brief
A vulnerability in Symantec Norton Utilities 2.0 for Windows 95 could allow a malicious website to run unauthorized commands on a user's computer. This occurs because a specific component of the software was incorrectly marked as safe for use by web browsers. If a user visits a compromised or malicious webpage using an older browser like Internet Explorer, an attacker could potentially take control of the system or access sensitive data.
Technical details
The TUNEOCX.OCX ActiveX control in Symantec Norton Utilities 2.0 for Windows 95 is incorrectly flagged as 'Safe for Scripting'. This allows a remote attacker to invoke the control's 'run' option through a malicious web page. When a user visits such a page using a browser that supports ActiveX (such as Internet Explorer 3.0), the attacker can execute arbitrary commands on the local system with the user's privileges. The attack requires the victim to navigate to a malicious URL, and the impact includes potential loss of confidentiality, integrity, and availability.
Affected products
- Symantec Norton Utilities 2.0 for Windows 95 2.0
Timeline
- 1997-05-04: disclosed: Initial publication date