Symantec/Norton Antivirus Flaw Threatens Millions of PCs

When you download antivirus software, you expect it to protect your computer, not threaten it. And yet for all the good that Symantec/Norton's security programs do, it turns out they may be able to do even more harm.

Credit: Dragon Image/Shutterstock

(Image credit: Dragon Image/Shutterstock)

An amazingly disastrous flaw could let cybercriminals attack a Windows machine at the deepest level, regardless of whether you have the home (Norton) or enterprise (Symantec) version of the company's programs — as do tens of millions of computers worldwide. Worse still: Not every system will get the fix automatically.

MORE: What?! Antivirus Software Could Make PCs More Vulnerable

This information comes from Google's Project Zero security-research blog, on which security boffin Tavis Ormandy periodically writes about the latest flaw he's discovered in commercial antivirus software.

In this case, the affected programs include, at the very least, Norton Security and its predecessors Norton 360, Norton AntiVirus and Norton Internet Security, as well as Symantec Endpoint Protection, Symantec Email Security, Symantec Protection Engine, Symantec Protection for SharePoint Servers, and pretty much any other antivirus product bearing the Symantec or its Norton imprints.

"These vulnerabilities are as bad as it gets," Ormandy wrote. "They don't require any user interaction, they affect the default configuration, and the software runs at the highest privilege levels possible."

Ormandy cited the flaws' susceptibility to both remote code execution and privilege escalation. This means that not only could an attacker take control of your computer remotely, but he or she could gain administrator access as well. From there, installing malware, stealing information or drafting it into a botnet would be trivial.

Explaining exactly how the flaws work is complicated, although you can read Ormandy's write-up for the full details. Essentially, when you download a compressed executable file (i.e., a program), an antivirus program decompresses, or "unpacks" the file to examine the file's code for vulnerabilities before the suspect file is opened or run.

The problem is that the unpacker program Symantec uses is itself vulnerable to attack, because it doesn't properly handle malformed software designed to confuse it. Mismatched parameters can trigger a memory-buffer overflow in the unpacker, letting an attacker slip in malicious code that can seize control of the Symantec or Norton antivirus software.

Users don't even need to open or run the malicious file. Just getting it on your system — for example, as an email attachment or web link — is enough, since Symantec's antivirus engine will scan and unpack it by default. (Ormandy noted that he has found similar flaws in antivirus products made by Kaspersky and ESET.)

This functionality is a risky proposition at the best of times, but Symantec's programs make it worse by unpacking and examining the suspicious compressed programs right in the Windows kernel, the deepest level of the operating system. That's like bringing a ticking time bomb into police headquarters to defuse it. Anyone who's had to remove a piece of malware that targeted the Windows kernel will tell you how nearly impossible it is to pry a stubborn bit of malware out of there.

Ormandy pointed out other buffer overflows and memory corruptions in the Symantec file unpacker, all of which could threaten PCs to a lesser degree. Symantec has pushed out patches for all of the flaws, but you may not be protected just yet.

First, the good news: There's no evidence that hackers were able to exploit these any of these flaws in the wild. Better news: Every affected Symantec program has been patched.

Still, enterprise users will have to do some legwork to protect themselves. LiveUpdate will take care of the patch for home users; otherwise, Symantec has provided a list of enterprise programs with instructions on how to patch each one. Needless to say, this update is probably even more critical for those who use Symantec to protect their businesses.

If there's a lesson to be learned from this, it's that no program is unhackable. The best an average user can do is to keep all of his or her software updated constantly — especially the software that keeps unwanted programs out.

TOPICS
Marshall Honorof

Marshall Honorof is a senior editor for Tom's Guide, overseeing the site's coverage of gaming hardware and software. He comes from a science writing background, having studied paleomammalogy, biological anthropology, and the history of science and technology. After hours, you can find him practicing taekwondo or doing deep dives on classic sci-fi. 

Latest in Antivirus
A woman using her laptop securely with a cup of coffee in hand
5 common mistakes people make when shopping for antivirus software
Best antivirus software
How does antivirus software work?
Avast software on a webpage
FTC rules Avast customers entitled to $16.5 million settlement — how to claim your share
A laptop with the screen displaying both the logos for Norton antivirus and McAfee antivirus softwares.
I compared Norton vs McAfee’s antivirus software to see which one is best
Bitdefender and Norton logo split a computer screen
I put Bitdefender vs Norton antivirus through a 7-round face-off — here's the winner
Norton 360 Standard (for Mac)
Norton 360 Deluxe is 75% off in this Black Friday deal — protect 5 PCs, Macs tablets or phones for just $30
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
Lewis Hamilton of Great Britain and Scuderia Ferrari looks on during Sprint Qualifying ahead of the F1 Grand Prix of China at Shanghai International Circuit in Shanghai, China, on March 21, 2025. (Photo by Song Haiyuan/Paddocker/NurPhoto via Getty Images)
How to watch Chinese Grand Prix 2025 online – stream F1 without cable, qualifying highlights
  • genej101
    I stopped using Norton when Peter sold out to Symantec - so a very long time ago. My work does still use the enterprise edition. Personally, I like standalone tools so use Sophos Home antivirus, Malware Bytes Pro software firewall and anti malware, a hardware firewall as basic protection; at least those are the most recent set, I've used others over the years and have yet to have a piece of malware or a virus get to my machine, ever, and I've been here online for well over 20 years. I've always considered Symantec bloatware and more nuisance than help given the incredibly difficulties in removing it - so their first suite was my last one. I do hope they get this fixed though as there are so many users dependent on it.
    Reply
  • lodders
    Last used Norton in 2002. Never again.

    The company I work for use Symantec for their data security. It still sucks.
    Reply