Symantec on Tuesday patched a vulnerability in its Enterprise Security Manager tool that could enable a hacker to remotely control an infected computer. The security vendor is warning users to update their software as soon as possible, saying this is a “high-risk” bug. All versions of ESM are vulnerable, except version 6.5.3, which includes the fixes and is not vulnerable.
A spokesman for Symantec said in an interview that the company isn’t aware of any proof-of-concept code or exploits for this vulnerability. The ESM tool is designed to discover and report vulnerabilities and security policy deviations, such as inappropriate passwords and missing patches.
The flaw lies in the fact that the tool does not authenticate someone who’s making an upgrade request. That means a hacker could use the flaw to infect the system with malware.
Symantec, Patch, Patches, High, Risk, Bug, Malwares, vulnerabilities, Report