CVE-2017-13681

3 documents3 sources
Severity
7.8HIGH
EPSS
0.1%
top 75.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateMay 13

Description

Symantec Endpoint Protection prior to SEP 12.1 RU6 MP9 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels. In the circumstances of this issue, the capability of exploit is limited by the need to perform multiple file and directory writes to the local filesystem and as such, is not feasible in a standard drive-by type attack.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-fj4f-frxp-mfr4: Symantec Endpoint Protection prior to SEP 122022-05-13
CVEList
CVE-2017-13681: Symantec Endpoint Protection prior to SEP 122017-11-06
CVE-2017-13681 (HIGH CVSS 7.8) | Symantec Endpoint Protection prior | cvebase.io