CVE-2009-1517 describes multiple insecure method vulnerabilities within the Symantec.EasySetup.1 ActiveX control (EasySetupInt.dll) in Symantec Norton Ghost 14.0's EasySetup wizard. These flaws allow remote attackers to trigger a denial of service (browser crash) and potentially execute arbitrary code by providing unspecified input to several methods, including GetBackupLocationPath and CallUninstall. With a CVSS score of 4.3, this vulnerability has a medium attack complexity and requires no authentication, but its primary impact is a denial of service. While not listed on the KEV catalog and having no active exploitation intelligence, a Proof-of-Concept exploit (EDB-8523) exists, though there is minimal community discussion or media coverage surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.0CPE matchmatch criteria | cpe:2.3:a:symantec:norton_ghost:14.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.