AV Bypass Vulnerability in Norton and Symantec Products
CVE-2018-12238

7.8HIGH

Key Information:

Vendor
Symantec Corporation
Status
Norton; Symantec Endpoint Protection (sep); Symantec Endpoint Protection Small Business Edition (sep Sbe); Symantec Endpoint Protection Cloud (sep Cloud)
Vendor
CVE Published:
29 November 2018

Summary

Norton and Symantec Endpoint Protection products are susceptible to an AV bypass issue due to flaws in virus detection mechanisms. Attackers can leverage this vulnerability by altering malicious files to avoid detection, thus compromising the effectiveness of security measures in place. This exploit specifically targets the signature-based detection methods within the antivirus engines, allowing malware to bypass security protocols.

Affected Version(s)

Norton; Symantec Endpoint Protection (SEP); Symantec Endpoint Protection Small Business Edition (SEP SBE); Symantec Endpoint Protection Cloud (SEP Cloud) Prior to 22.15 [Norton]

Norton; Symantec Endpoint Protection (SEP); Symantec Endpoint Protection Small Business Edition (SEP SBE); Symantec Endpoint Protection Cloud (SEP Cloud) Prior to 12.1.7454.7000 & 14.2 [Symantec Endpoint Protection (SEP)]

Norton; Symantec Endpoint Protection (SEP); Symantec Endpoint Protection Small Business Edition (SEP SBE); Symantec Endpoint Protection Cloud (SEP Cloud) Prior to NIS-22.15.1.8 & SEP-12.1.7454.7000 [Symantec Endpoint Protection Small Business Edition (SEP SBE)]

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.