Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2018-5238
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a specific search path to locate the DLL. The vulnerability can be exploited by a simple file write (or potentially an over-write) which results in a foreign DLL running under the context of the application.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Symantec Norton Power Eraser和SymDiag 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Symantec Norton Power Eraser和SymDiag都是美国赛门铁克(Symantec)公司的产品。Symantec Norton Power Eraser是一款具有主动监测技术的恶意程序扫描工具。SymDiag是一款支持多种语言的Symantec产品诊断和安全分析实用程序。 Symantec Norton Power Eraser 5.3.0.24之前版本和SymDiag 2.1.242之前版本中存在DLL预加载漏洞。攻击者可通过写入或覆盖文件利用该漏洞在应用程序的上下文中运行恶意的
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Symantec CorporationNorton Power Eraser Prior to 5.3.0.24 -
Symantec CorporationSymDiag Prior to 2.1.242 -
II. Public POCs for CVE-2018-5238
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2018-5238
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2018-5238

No comments yet


Leave a comment