CVE-2009-1517

critical

Description

Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Symantec Norton Ghost 14.0 allow remote attackers to cause a denial of service (browser crash) and possibly execute arbitrary code via unspecified input to the (1) GetBackupLocationPath, (2) CallUninstall, (3) SetupDeleteVolume, (4) CanUseEasySetup, (5) CallAddInitialProtection, and (6) CallTour methods.

References

https://www.exploit-db.com/exploits/8523

https://exchange.xforce.ibmcloud.com/vulnerabilities/50098

https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1514

http://www.shinnai.net/xplits/TXT_Gl6RHStS23c9DANArcJE.html

http://www.securitytracker.com/id?1022120

http://www.securityfocus.com/bid/34696

Details

Source: Mitre, NVD

Published: 2009-05-04

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.06586