DLL Preloading Vulnerability in Norton Security for Windows by Symantec
CVE-2018-18369

7.8HIGH

Key Information:

Vendor
Symantec Corporation
Status
Norton Security
Symantec Endpoint Protection Small Business Edition
Vendor
CVE Published:
25 April 2019

Summary

Norton Security for Windows and SEP SBE are vulnerable to a DLL Preloading issue, where an application may inadvertently execute a malicious DLL provided by an attacker, potentially leading to unauthorized actions within the affected software. This vulnerability affects multiple versions and poses a risk to users who may be unaware of the exploit.

Affected Version(s)

Norton Security Prior to 22.16.3

Symantec Endpoint Protection Small Business Edition Prior to Cloud Agent 3.00.31.2817

Symantec Endpoint Protection Small Business Edition NIS-22.15.2.22

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.