CVE-2018-18369

CWE-4263 documents3 sources
Severity
7.8HIGH
EPSS
0.8%
top 25.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25
Latest updateMay 24

Description

Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5symantec_corporation/norton_securityPrior to 22.16.3
NVDsymantec/endpoint_protectionnis-22.15.2.22, sep-12.1.7484.7002+1

🔴Vulnerability Details

2
GHSA
GHSA-cqr9-3mc7-gvpr: Norton Security (Windows client) prior to 222022-05-24
CVEList
CVE-2018-18369: Norton Security (Windows client) prior to 222019-04-25