7.8

CVE-2018-18367

Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SymantecEndpoint Protection Manager Version12.1 Updatertm
SymantecEndpoint Protection Manager Version12.1 Updateru1
SymantecEndpoint Protection Manager Version12.1 Updateru1-mp1
SymantecEndpoint Protection Manager Version12.1 Updateru2
SymantecEndpoint Protection Manager Version12.1 Updateru2-mp1
SymantecEndpoint Protection Manager Version12.1 Updateru3
SymantecEndpoint Protection Manager Version12.1 Updateru4
SymantecEndpoint Protection Manager Version12.1 Updateru4-mp1
SymantecEndpoint Protection Manager Version12.1 Updateru4-mp1a
SymantecEndpoint Protection Manager Version12.1 Updateru4-mp1b
SymantecEndpoint Protection Manager Version12.1 Updateru4a
SymantecEndpoint Protection Manager Version12.1 Updateru5
SymantecEndpoint Protection Manager Version12.1 Updateru6
SymantecEndpoint Protection Manager Version12.1 Updateru6-mp1
SymantecEndpoint Protection Manager Version12.1 Updateru6-mp1a
SymantecEndpoint Protection Manager Version12.1 Updateru6-mp2
SymantecEndpoint Protection Manager Version12.1 Updateru6-mp3
SymantecEndpoint Protection Manager Version12.1 Updateru6-mp4
SymantecEndpoint Protection Manager Version12.1 Updateru6-mp5
SymantecEndpoint Protection Manager Version12.1 Updateru6-mp6
SymantecEndpoint Protection Manager Version12.1 Updateru6-mp7
SymantecEndpoint Protection Manager Version12.1 Updateru6-mp8
SymantecEndpoint Protection Manager Version12.1 Updateru6-mp9
SymantecEndpoint Protection Manager Version14 Updatemp1
SymantecEndpoint Protection Manager Version14 Updatemp2
SymantecEndpoint Protection Manager Version14.0.1 Updatemp1
SymantecEndpoint Protection Manager Version14.0.1 Updatemp2
SymantecEndpoint Protection Manager Version14.2 Updatemp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.575
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-426 Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.