CVE-2015-1492

Severity
8.5HIGH
EPSS
0.8%
top 25.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateMay 17

Description

Untrusted search path vulnerability in the client in Symantec Endpoint Protection 12.1 before 12.1-RU6-MP1 allows local users to gain privileges via a Trojan horse DLL in a client install package.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 6.8 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-wrh7-vv7r-8w3q: Untrusted search path vulnerability in the client in Symantec Endpoint Protection 122022-05-17
CVEList
CVE-2015-1492: Untrusted search path vulnerability in the client in Symantec Endpoint Protection 122015-08-01

💬Community

1
Bugzilla
CVE-2015-1855 ruby: OpenSSL extension hostname matching implementation violates RFC 61252015-04-08
CVE-2015-1492 (HIGH CVSS 8.5) | Untrusted search path vulnerability | cvebase.io