Remote Code Execution Vulnerability in Symantec Enterprise Security Manager
CVE-2007-2375

Currently unrated

Key Information:

Vendor

Symantec

Vendor
CVE Published:
30 April 2007

What is CVE-2007-2375?

The remote upgrade interface in Symantec's Enterprise Security Manager (ESM) prior to version 20070405 fails to authenticate the legitimacy of upgrade processes. This vulnerability enables remote attackers to exploit the agent upgrade protocol and potentially execute arbitrary code on the system. Due to this flaw, organizations utilizing affected versions of ESM may face significant security risks, allowing unauthorized access and control over sensitive systems.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.