Vulnerability Intelligence Report
CVE-2010-0108
Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:19.41%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| symantec | antivirus | 10.0, 10.0.1, 10.0.1.1, 10.0.2, 10.0.2.1, 10.0.2.2, 10.0.3, 10.0.4, 10.0.5, 10.0.6, 10.0.7, 10.0.8, 10.0.9, 10.1, 10.1.0.1, 10.1.4, 10.1.4.1, 10.1.5, 10.1.5.1, 10.1.6, 10.1.6.1, 10.1.7, 10.2 |
| symantec | client_security | 3.0, 3.0.0.359, 3.0.1.1000, 3.0.1.1007, 3.0.1.1008, 3.0.2, 3.0.2.2000, 3.0.2.2001, 3.0.2.2010, 3.0.2.2011, 3.0.2.2020, 3.0.2.2021, 3.1, 3.1.0.396, 3.1.0.401, 3.1.394, 3.1.400, 3.1.401 |
| symantec | endpoint_protection | 11.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
19.405%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2009-12-31T00:00:00 |
| Published | 2010-02-19T17:00:00 |
| Patch Date | 2010-02-17 |
| Last Updated | 2024-08-07T00:37:54 |
Community Chatter & Buzz