High severity7.8NVD Advisory· Published May 11, 2020· Updated Jun 17, 2026
CVE-2020-5837
CVE-2020-5837
Description
Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.
Affected products
3cpe:2.3:a:symantec:endpoint_protection:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:symantec:endpoint_protection:*:*:*:*:*:*:*:*range: <14.3
- (no CPE)range: <14.3
- Range: <14.3
Patches
Vulnerability mechanics
References
1- support.broadcom.com/security-advisory/security-advisory-detail.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.