Permissions, Privileges, and Access Controls in Symantec Mail Security for Microsoft Exchange (SMSMSE) and Symantec Endpoint Protection Manager - CVE-2019-12759

 

Permissions, Privileges, and Access Controls in Symantec Mail Security for Microsoft Exchange (SMSMSE) and Symantec Endpoint Protection Manager - CVE-2019-12759

Published: November 18, 2019


Vulnerability identifier: #VU22818
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12759
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper permission checks. A local user can compromise the software application and gain elevated privileges on the system.

Affected software

Symantec Mail Security for Microsoft Exchange (SMSMSE)
Symantec Endpoint Protection Manager

How to mitigate CVE-2019-12759

Install updates from vendor's website.

Symantec Mail Security for Microsoft Exchange (SMSMSE) - update to 7.9
Symantec Endpoint Protection Manager - update to 14.2 RU2

External References

Related Security Bulletins