Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-12245

Опубликовано: 29 нояб. 2018
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case is an issue that can occur when an application being installed unintentionally loads a DLL provided by a potential attacker. Note that this particular type of exploit only manifests at install time; no remediation is required for software that has already been installed. This issue only impacted the Trialware media for Symantec Endpoint Protection, which has since been updated.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:symantec:endpoint_protection:*:*:*:*:*:*:*:*
Версия от 11.0 (включая) до 14.2.0.1 (включая)

EPSS

Процентиль: 46%
0.00236
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case is an issue that can occur when an application being installed unintentionally loads a DLL provided by a potential attacker. Note that this particular type of exploit only manifests at install time; no remediation is required for software that has already been installed. This issue only impacted the Trialware media for Symantec Endpoint Protection, which has since been updated.

EPSS

Процентиль: 46%
0.00236
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-426