Privilege Escalation Vulnerability in Symantec Endpoint Protection by Broadcom
CVE-2022-37016

9.8CRITICAL

Key Information:

Vendor
Broadcom
Vendor
CVE Published:
1 December 2022

Summary

The Symantec Endpoint Protection (Windows) agent is vulnerable to an exploit that allows attackers to gain elevated access to restricted resources. This vulnerability could enable unauthorized manipulation of the security application, thereby compromising system integrity. Protecting against this type of threat involves ensuring that the software is updated and regularly monitored for unusual activity.

Affected Version(s)

Symantec Endpoint Protection 14.3 RU5

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.