VYPR

Symantec Endpoint Protection

by Chatwoot

CVEs (7)

  • CVE-2022-37017Dec 1, 2022
    risk 0.01cvss epss 0.08

    Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.

  • CVE-2022-25631Jan 20, 2023
    risk 0.00cvss epss 0.00

    Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated

  • CVE-2022-37016Dec 1, 2022
    risk 0.00cvss epss 0.01

    Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

  • CVE-2020-5837May 11, 2020
    risk 0.00cvss epss 0.02

    Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.

  • CVE-2020-5836May 11, 2020
    risk 0.00cvss epss 0.00

    Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec Endpoint Protection's Tamper Protection feature is disabled.

  • CVE-2019-18372Nov 15, 2019
    risk 0.00cvss epss 0.00

    Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

  • CVE-2019-12758Nov 15, 2019
    risk 0.00cvss epss 0.00

    Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which may allow an individual to execute code without a resident proper digital signature.