Privilege Escalation Vulnerability in Symantec Management Agent by Broadcom
CVE-2022-25623

7.8HIGH

Key Information:

Vendor
Symantec
Vendor
CVE Published:
4 March 2022

Summary

The Symantec Management Agent is exposed to a privilege escalation issue that enables a low-privileged local user to gain SYSTEM-level access. This security flaw is exploited via manipulation of the Windows registry, which can lead to unauthorized activities on the affected system. Organizations using this agent should promptly review their configurations and apply necessary measures to mitigate potential risks.

Affected Version(s)

Symantec Management Agent 8.5, 8.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.