PT-2019-12919 · Symantec · Symantec Endpoint Protection Small Business Edition+2
Publicado
2019-07-31
·
Atualizado
2020-08-24
·
CVE-2019-12750
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Symantec Endpoint Protection versions prior to 14.2 RU1
Symantec Endpoint Protection versions 12.1 prior to RU6 MP10
Symantec Endpoint Protection Small Business Edition versions 12.1 prior to RU6 MP10c (12.1.7491.7002)
Description
The issue is a privilege escalation vulnerability, which allows an attacker to attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. This is a type of issue where an attacker may try to exploit the software to gain higher privileges.
Recommendations
For Symantec Endpoint Protection versions prior to 14.2 RU1, update to version 14.2 RU1 or later.
For Symantec Endpoint Protection versions 12.1 prior to RU6 MP10, update to version 12.1 RU6 MP10 or later.
For Symantec Endpoint Protection Small Business Edition versions 12.1 prior to RU6 MP10c (12.1.7491.7002), update to version 12.1 RU6 MP10c (12.1.7491.7002) or later.
Exploit
Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Symantec Endpoint Protection
Symantec Endpoint Protection Client
Symantec Endpoint Protection Small Business Edition