PT-2017-9948 · Symantec · Symantec Endpoint Protection+1
Published
2017-03-06
·
Updated
2018-05-22
·
CVE-2016-9094
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Symantec Endpoint Protection versions prior to 14.0 MP1
Symantec Endpoint Protection versions prior to 12.1 RU6 MP7
Description
The issue concerns the export of quarantine logs in CSV format, which can potentially allow attackers to inject formulas due to the interpretation of file metadata. Successful exploitation requires significant direct user interaction, including exporting and opening the log files on the target client.
Recommendations
For versions prior to 14.0 MP1, update to version 14.0 MP1 or later to resolve the issue.
For versions prior to 12.1 RU6 MP7, update to version 12.1 RU6 MP7 or later to resolve the issue.
As a temporary workaround, consider avoiding the export of quarantine logs in CSV format until a patch is applied.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Symantec Endpoint Protection
Symantec Endpoint Protection Client