vendor:
Endpoint Protection
by:
41.w4r10r
9,3
CVSS
HIGH
Local Code Execution
94
CWE
Product Name: Endpoint Protection
Affected Version From: 11.0 RU6
Affected Version To: 11.0 RU7-MP1
Patch Exists: YES
Related CWE: CVE-2012-0289
CPE: a:symantec:endpoint_protection:11.0
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 English, Windows XP SP3 English, Windows Vista 32Bit, Windows 7 32Bit
2012
Symantec End Point Protection 11.x & Symantec Network Access Control 11.x Local Code Execution POC
A vulnerability exists in Symantec End Point Protection 11.x & Symantec Network Access Control 11.x due to improper validation of user-supplied input. An attacker can exploit this vulnerability by crafting a malicious XML file and sending it to the vulnerable system. This can allow the attacker to execute arbitrary code on the vulnerable system.
Mitigation:
Users should upgrade to the latest version of Symantec End Point Protection 11.x & Symantec Network Access Control 11.x to mitigate this vulnerability.