Skip to main content

Symantec Endpoint Protection Elevated Privilege Vulnerabilities

Last Update Date: 13 Jan 2014 15:31 Release Date: 13 Jan 2014 3396 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities have been identified in Symantec Endpoint Protection, which can be exploited by local user obtain elevated privileges on the vulnerable system.

  1. A local user can exploit an authentication flaw in the Management Console to gain the privileges of another user.
  2. A local user can bypass custom Application/Device Control (ADC) policies to access directories and files on the target system.
  3. A local user can exploit an unquoted search path to execute arbitrary code with elevated privileges.

Impact

  • Elevation of Privilege
  • Security Restriction Bypass

System / Technologies affected

  • Symantec Endpoint Protection 11.x
  • Symantec Endpoint Protection 12.0
  • Symantec Endpoint Protection 12.1.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Apply the vendor patch

Vulnerability Identifier


Source


Related Link