6.5

CVE-2018-18366

Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can cause the driver to return uninitialized memory.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SymantecEndpoint Protection Version11.0 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updatemr1 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updatemr2 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updatemr3 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updatemr4 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updatemr4-mp2 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru5 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru6 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru6-mp1 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru6-mp2 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru6-mp3 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru6a SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru7 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru7-mp1 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru7-mp2 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru7-mp4 SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updateru7-mp4a SwPlatformwindows
SymantecEndpoint Protection Version11.0 Updatery7-mp3 SwPlatformwindows
SymantecEndpoint Protection Version12.1 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru1 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru1-mp1 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru2 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru2-mp1 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru3 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru4 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru4-mp1 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru4-mp1a SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru4-mp1b SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru4a SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru5 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru6 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru6-mp1 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru6-mp10 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru6-mp2 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru6-mp3 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru6-mp4 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru6-mp5 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru6-mp6 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru6-mp7 SwPlatformwindows
SymantecEndpoint Protection Version12.1 Updateru6-mp8 SwPlatformwindows
SymantecEndpoint Protection Version14 SwPlatformwindows
SymantecEndpoint Protection Version14 Updatemp1 SwPlatformwindows
SymantecEndpoint Protection Version14.0.0 Updatemp2 SwPlatformwindows
SymantecEndpoint Protection Version14.0.1 SwPlatformwindows
SymantecEndpoint Protection Version14.0.1 Updatemp1 SwPlatformwindows
SymantecEndpoint Protection Version14.0.1 Updatemp2 SwPlatformwindows
SymantecEndpoint Protection Version14.2 SwPlatformwindows
SymantecEndpoint Protection Version14.2 Updatemp1 SwPlatformwindows
SymantecEndpoint Protection Versionnis-22.15.2.22 SwEditionsmall_business
SymantecEndpoint Protection Versionsep-12.1.7484.7002 SwEditionsmall_business
SymantecEndpoint Protection Cloud Version < 22.16.3
SymantecEndpoint Protection Cloud Agent SwEditionsmall_business Version < 3.00.31.2817
SymantecNorton Security SwPlatformwindows Version < 22.16.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.219
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2 4
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.