Uncaught Exception in Broadcom products - CVE-2020-12597
Published: June 21, 2021
Vulnerability identifier: #VU54290
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12597
CWE-ID: CWE-248
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to uncaught exception in a common driver. A local user can perform a denial of service attack.
Affected software
Symantec Endpoint Protection
Cloud Workload Protection (CWP) Windows Client
Data Center Security (DCS) Windows Agent
Cloud Workload Protection (CWP) Windows Client
Data Center Security (DCS) Windows Agent
How to mitigate CVE-2020-12597
Install updates from vendor's website.
Symantec Endpoint Protection - update to 14.3 RU1 MP1
Cloud Workload Protection (CWP) Windows Client - update to 1.6.1
Data Center Security (DCS) Windows Agent - update to 6.9.1
Cloud Workload Protection (CWP) Windows Client - update to 1.6.1
Data Center Security (DCS) Windows Agent - update to 6.9.1