Risk: High
Two flaws have been found in a variety of Symantec programs, which can permit malicious attackers to gain system access.
The vulnerabilities are caused due to errors in the AxSysListView32 and AxSysListView32OAA ActiveX controls (NavComUI.dll) when handling the 'AnomalyList' and 'Anomaly' properties respectively as they take a VARIANT* as argument.
Symantec customers will receive a patch via LiveUpdate and Symantec isn't aware of any instances of the flaw having been exploited.
Symantec has issued an advisory, which is available at:
http://www.symantec.com/avcenter/security/Content/2007.08.09.html