Permissions, Privileges, and Access Controls in Symantec Mail Security for Microsoft Exchange (SMSMSE) and Symantec Endpoint Protection Manager - CVE-2019-12759
Published: November 18, 2019
Vulnerability identifier: #VU22818
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12759
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper permission checks. A local user can compromise the software application and gain elevated privileges on the system.Affected software
Symantec Mail Security for Microsoft Exchange (SMSMSE)
Symantec Endpoint Protection Manager
Symantec Endpoint Protection Manager
How to mitigate CVE-2019-12759
Install updates from vendor's website.
Symantec Mail Security for Microsoft Exchange (SMSMSE) - update to 7.9
Symantec Endpoint Protection Manager - update to 14.2 RU2
Symantec Endpoint Protection Manager - update to 14.2 RU2