PT-2017-9948 · Symantec · Symantec Endpoint Protection+1

Publicado

2017-03-06

·

Atualizado

2018-05-22

·

CVE-2016-9094

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Symantec Endpoint Protection versions prior to 14.0 MP1 Symantec Endpoint Protection versions prior to 12.1 RU6 MP7
Description The issue concerns the export of quarantine logs in CSV format, which can potentially allow attackers to inject formulas due to the interpretation of file metadata. Successful exploitation requires significant direct user interaction, including exporting and opening the log files on the target client.
Recommendations For versions prior to 14.0 MP1, update to version 14.0 MP1 or later to resolve the issue. For versions prior to 12.1 RU6 MP7, update to version 12.1 RU6 MP7 or later to resolve the issue. As a temporary workaround, consider avoiding the export of quarantine logs in CSV format until a patch is applied.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9094

Produtos afetados

Symantec Endpoint Protection
Symantec Endpoint Protection Client