vendor:
Endpoint Protection Manager
by:
st3n@funoverip.net (a.k.a. jerome.nokin@gmail.com)
7,8
CVSS
HIGH
SEH Overflow
119
CWE
Product Name: Endpoint Protection Manager
Affected Version From: 12.1.0
Affected Version To: 12.1.2
Patch Exists: YES
Related CWE: CVE-2013-1612
CPE: a:symantec:endpoint_protection_manager
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2003 Enterprise Edition SP2
2013
Symantec Endpoint Protection Manager 12.1.x – SEH Overflow POC
This POC code overwrites EIP with 'CCCCCCCC'. The KCS key is used to obfuscate traffic between client and server and is generated during SEPM installation. It can be found in the SyLink.xml file on the client station or in the ersecreg.log file on the server side.
Mitigation:
Update to the latest version of Symantec Endpoint Protection Manager.