peter bassill · operator
$ cve CVE-2009-1517 JSON

CVE-2009-1517 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 6.6% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Symantec Norton Ghost 14.0 allow remote attackers to cause a denial of service (browser crash) and possibly execute arbitrary code via unspecified input to the (1) GetBackupLocationPath, (2) CallUninstall, (3) SetupDeleteVolume, (4) CanUseEasySetup, (5) CallAddInitialProtection, and (6) CallTour methods.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS6.59% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2009-05-04
Last modified2026-06-16

Affected (1)

VendorProduct
symantecnorton ghost

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD