PT-2017-9948 · Symantec · Symantec Endpoint Protection+1

Published

2017-03-06

·

Updated

2018-05-22

·

CVE-2016-9094

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Symantec Endpoint Protection versions prior to 14.0 MP1 Symantec Endpoint Protection versions prior to 12.1 RU6 MP7
Description The issue concerns the export of quarantine logs in CSV format, which can potentially allow attackers to inject formulas due to the interpretation of file metadata. Successful exploitation requires significant direct user interaction, including exporting and opening the log files on the target client.
Recommendations For versions prior to 14.0 MP1, update to version 14.0 MP1 or later to resolve the issue. For versions prior to 12.1 RU6 MP7, update to version 12.1 RU6 MP7 or later to resolve the issue. As a temporary workaround, consider avoiding the export of quarantine logs in CSV format until a patch is applied.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9094

Affected Products

Symantec Endpoint Protection
Symantec Endpoint Protection Client