9.8
CVSSv3

CVE-2001-1125

Published: 05/10/2001 Updated: 08/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Symantec LiveUpdate prior to 1.6 does not use cryptography to ensure the integrity of download files, which allows remote malicious users to execute arbitrary code via DNS spoofing of the update.symantec.com site.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec liveupdate