Symantec Endpoint Encryption vulnerabilities

10 known vulnerabilities affecting symantec/endpoint_encryption.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM4LOW1

Vulnerabilities

Page 1 of 1
CVE-2016-6590HIGHCVSS 7.8≥ 7.0, < 7.6v7.62020-01-08
CVE-2016-6590 [HIGH] CWE-269 CVE-2016-6590: A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a loca
nvd
CVE-2019-9703HIGHCVSS 7.8fixed in 11.3.0vPrior to SEE 11.3.02019-07-01
CVE-2019-9703 [HIGH] CVE-2019-9703: Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vuln Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
cvelistv5nvd
CVE-2019-9702HIGHCVSS 7.8fixed in 11.3.0vPrior to SEE 11.3.02019-07-01
CVE-2019-9702 [HIGH] CVE-2019-9702: Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vuln Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
cvelistv5nvd
CVE-2019-9694HIGHCVSS 7.8v11.0v11.1+4 more2019-04-10
CVE-2019-9694 [HIGH] CVE-2019-9694: Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vu Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
nvd
CVE-2017-15525MEDIUMCVSS 4.5≤ 11.1.32017-11-13
CVE-2017-15525 [MEDIUM] CVE-2017-15525: Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a denial of service (DoS Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a denial of service (DoS) attack, which is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a specific host within a network.
nvd
CVE-2017-15526MEDIUMCVSS 6.8≤ 11.1.32017-11-13
CVE-2017-15526 [MEDIUM] CWE-476 CVE-2017-15526: Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a null pointer de-refere Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a null pointer de-reference issue, which can result in a NullPointerException that can lead to a privilege escalation scenario.
nvd
CVE-2017-13683MEDIUMCVSS 5.7v11.0.0v11.1.0+2 more2017-10-23
CVE-2017-13683 [MEDIUM] CWE-772 CVE-2017-13683: In Symantec Endpoint Encryption before SEE 11.1.3HF3, a kernel memory leak is a type of resource lea In Symantec Endpoint Encryption before SEE 11.1.3HF3, a kernel memory leak is a type of resource leak that can occur when a computer program incorrectly manages memory allocations in such a way that memory which is no longer needed is not released. In object-oriented programming, a memory leak may happen when an object is stored in memory but cannot
nvd
CVE-2017-13675MEDIUMCVSS 4.2≤ 11.1.32017-10-10
CVE-2017-13675 [MEDIUM] CVE-2017-13675: A denial of service (DoS) attack in Symantec Endpoint Encryption before SEE 11.1.3HF2 allows remote A denial of service (DoS) attack in Symantec Endpoint Encryption before SEE 11.1.3HF2 allows remote attackers to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a specific host within a network.
nvd
CVE-2015-8156HIGHCVSS 7.8v11.0v11.0.0+1 more2016-05-14
CVE-2015-8156 [HIGH] CVE-2015-8156: Unquoted Windows search path vulnerability in EEDService in Symantec Endpoint Encryption (SEE) 11.x Unquoted Windows search path vulnerability in EEDService in Symantec Endpoint Encryption (SEE) 11.x before 11.1.1 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.
nvd
CVE-2015-6556LOWCVSS 2.3≤ 11.02015-12-18
CVE-2015-6556 [LOW] CWE-200 CVE-2015-6556: EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) b EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows remote authenticated users to discover credentials by triggering a memory dump.
nvd