Race Condition Issue in Symantec Endpoint Protection
CVE-2015-8801

2.9LOW

Key Information:

Vendor
Symantec
Vendor
CVE Published:
30 June 2016

Summary

A race condition in the client of Symantec Endpoint Protection prior to RU6 MP5 enables local users to circumvent the intended USB file transfer restrictions. This vulnerability arises when filesystem operations occur before the Symantec device manager can identify and manage a newly connected USB device. As a result, unauthorized access to sensitive files can take place, posing a significant security risk.

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.