PT-2019-12919 · Symantec · Symantec Endpoint Protection Small Business Edition+2

Published

2019-07-31

·

Updated

2020-08-24

·

CVE-2019-12750

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Symantec Endpoint Protection versions prior to 14.2 RU1 Symantec Endpoint Protection versions 12.1 prior to RU6 MP10 Symantec Endpoint Protection Small Business Edition versions 12.1 prior to RU6 MP10c (12.1.7491.7002)
Description The issue is a privilege escalation vulnerability, which allows an attacker to attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. This is a type of issue where an attacker may try to exploit the software to gain higher privileges.
Recommendations For Symantec Endpoint Protection versions prior to 14.2 RU1, update to version 14.2 RU1 or later. For Symantec Endpoint Protection versions 12.1 prior to RU6 MP10, update to version 12.1 RU6 MP10 or later. For Symantec Endpoint Protection Small Business Edition versions 12.1 prior to RU6 MP10c (12.1.7491.7002), update to version 12.1 RU6 MP10c (12.1.7491.7002) or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12750

Affected Products

Symantec Endpoint Protection
Symantec Endpoint Protection Client
Symantec Endpoint Protection Small Business Edition