The two companies said three of the vulnerabilities allow attackers to gain access to the machine with code execution privileges. The third is a denial-of-service vulnerability that would require a reboot to resolve.

The vulnerabilities are all in the symdns.sys component of the software, which handles how the firewall software handles DNS messages. eEye described the vulnerabilities as grave. Symantec’s patches are available via its LiveUpdate service.

eEye, and other security research companies, have been lately focusing much of their research on firewall software because, they say, that’s where the bad guys are looking for ways into networks.