← Vulnerability feed

Vulnerability record · CVE-2009-1517 · published 4 May 2009

CVE-2009-1517: Symantec norton ghost vulnerability

Symantec · Norton Ghost

Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Symantec Norton Ghost 14.0 allow remote attackers to cause a denial of service (browser crash) and possibly execute arbitrary code via unspecified input to the (1) GetBackupLocationPath, (2) CallUninstall, (3) SetupDeleteVolume, (4) CanUseEasySetup, (5) CallAddInitialProtection, and (6) CallTour methods.

4.3 CVSS 2.0 Medium EPSS 6.6% · top 6.4%
4.3CVSS 2.0 base score
6.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Symantec Norton Ghost 14.0 allow remote attackers to cause a denial of service (browser crash) and possibly execute arbitrary code via unspecified input to the (1) GetBackupLocationPath, (2) CallUninstall, (3) SetupDeleteVolume, (4) CanUseEasySetup, (5) CallAddInitialProtection, and (6) CallTour methods.

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-1517 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2007-3666Symantec norton ghost vulnerabilityBuffer overflow in RemoteCommand.DLL in Symantec Norton Ghost 12.0 allows remote attackers to execute arbitrary code via the Connect function.EPSS 3.0%7.5CVE-2002-0345Symantec norton ghost vulnerabilitySymantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.EPSS 1.6%7.2CVE-2007-2359Symantec backupexec system recovery vulnerabilityBuffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recover…EPSS 0.41%6.8CVE-2007-2360Symantec backupexec system recovery vulnerabilitySymantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore poi…EPSS 0.34%5.5CVE-2011-3477Symantec backup exec system recovery improper input validation vulnerabilityGEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery…EPSS 0.62%5.0CVE-2007-3665Symantec norton ghost vulnerabilityMultiple unspecified vulnerabilities in FileBackup.DLL in Symantec Norton Ghost 12.0 allow remote attackers to cause a denial of service via unspecif…EPSS 1.5%5.0CVE-2007-3132Symantec ghost solutions suite vulnerabilityMultiple vulnerabilities in Symantec Ghost Solution Suite 2.0.0 and earlier, with Ghost 8.0.992 and possibly other versions, allow remote attackers t…EPSS 2.2%5.0CVE-2001-0598Symantec norton ghost vulnerabilitySymantec Ghost 6.5 and earlier allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to the Ghost Configur…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2009-1517), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.