Symantec Norton AntiVirus MS-DOS Name Scan Evasion Vulnerability
10 Apr. 2012
Summary
This allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.
Norton AntiVirus is affected by a scan evasion vulnerability when handling files with MS-DOS reserve device names. This issue is due to a design error that allows the files to avoid being scanned. It should be noted that this vulnerability only arises once the file is already present on a vulnerable computer. All Norton AntiVirus products are able to detect malicious files through incoming email.
Vendor Status:
Symantec as issued an update for this vulnerablity