BlackKite: Home
Menu

PUBLISHED DATE: December 31, 2002CVE-2002-1777:
NOTE: this issue has...

CVSS:
7.5
EPSS:
53.40%
Exploitability:
10
In KEV:
No
Description

NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass e-mail scanning via a filename in the Content-Type field with an excluded extension such as .nch or .dbx, but a malicious extension in the Content-Disposition field, which is used by Outlook to obtain the file name. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but Norton AntiVirus or the Office plug-in would detect the virus before it is executed

Products
Questions to Ask Vendors
  1. Can you confirm whether your systems are affected by CVE-2002-1777, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2002-1777 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
References

Ready to get results you can trust?