PT-2019-12919 · Symantec · Symantec Endpoint Protection Small Business Edition+2
Published
2019-07-31
·
Updated
2020-08-24
·
CVE-2019-12750
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Symantec Endpoint Protection versions prior to 14.2 RU1
Symantec Endpoint Protection versions 12.1 prior to RU6 MP10
Symantec Endpoint Protection Small Business Edition versions 12.1 prior to RU6 MP10c (12.1.7491.7002)
Description
The issue is a privilege escalation vulnerability, which allows an attacker to attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. This is a type of issue where an attacker may try to exploit the software to gain higher privileges.
Recommendations
For Symantec Endpoint Protection versions prior to 14.2 RU1, update to version 14.2 RU1 or later.
For Symantec Endpoint Protection versions 12.1 prior to RU6 MP10, update to version 12.1 RU6 MP10 or later.
For Symantec Endpoint Protection Small Business Edition versions 12.1 prior to RU6 MP10c (12.1.7491.7002), update to version 12.1 RU6 MP10c (12.1.7491.7002) or later.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Symantec Endpoint Protection
Symantec Endpoint Protection Client
Symantec Endpoint Protection Small Business Edition