PT-2020-18734 · Symantec · Symantec Endpoint Protection+3

Published

2020-02-11

·

Updated

2021-07-21

·

CVE-2020-5825

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Symantec Endpoint Protection versions prior to 14.2 RU2 MP1 Symantec Endpoint Protection Small Business Edition versions prior to 14.2.5569.2100
Description The issue allows an attacker to overwrite existing files on the system without proper privileges, which is a type of arbitrary file write vulnerability. This can be exploited to move or rename files arbitrarily. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For Symantec Endpoint Protection versions prior to 14.2 RU2 MP1, update to version 14.2 RU2 MP1 or later. For Symantec Endpoint Protection Small Business Edition versions prior to 14.2.5569.2100, update to version 14.2.5569.2100 or later. As a temporary workaround, consider restricting access to the AvHostPlugin to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-5825
ZDI-20-226
ZDI-20-227
ZDI-20-228

Affected Products

Avhostplugin
Symantec Endpoint Protection
Symantec Endpoint Protection Client
Symantec Endpoint Protection Small Business Edition