Unsigned Code Execution Vulnerability in Symantec Endpoint Protection
CVE-2019-12758

6.7MEDIUM

Key Information:

Vendor
Symantec
Vendor
CVE Published:
15 November 2019

Summary

Symantec Endpoint Protection, prior to version 14.2 RU2, is vulnerable to an unsigned code execution vulnerability. This flaw enables attackers to execute malicious code without proper digital signatures, bypassing security measures implemented for application integrity. Organizations using affected versions may face significant security risks, potentially allowing unauthorized access or control of their endpoints. It is crucial for users to upgrade to the latest version to mitigate possible exploitation.

Affected Version(s)

Symantec Endpoint Protection prior to 14.2 RU2

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.