DLL Preloading Vulnerability in Norton Security for Windows by Symantec
CVE-2018-18369
7.8HIGH
Key Information:
- Vendor
- Symantec Corporation
- Status
- Norton Security
- Symantec Endpoint Protection Small Business Edition
- Vendor
- CVE Published:
- 25 April 2019
Summary
Norton Security for Windows and SEP SBE are vulnerable to a DLL Preloading issue, where an application may inadvertently execute a malicious DLL provided by an attacker, potentially leading to unauthorized actions within the affected software. This vulnerability affects multiple versions and poses a risk to users who may be unaware of the exploit.
Affected Version(s)
Norton Security Prior to 22.16.3
Symantec Endpoint Protection Small Business Edition Prior to Cloud Agent 3.00.31.2817
Symantec Endpoint Protection Small Business Edition NIS-22.15.2.22
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved