#VU25321 Insecure DLL loading in Symantec Endpoint Protection and Symantec Endpoint Protection Small Business Edition


Published: 2020-02-13

Vulnerability identifier: #VU25321

Vulnerability risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-5821

CWE-ID: CWE-427

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Symantec Endpoint Protection
Client/Desktop applications / Antivirus software/Personal firewalls
Symantec Endpoint Protection Small Business Edition
Client/Desktop applications / Antivirus software/Personal firewalls

Vendor: Broadcom

Description

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local user can use a specially crafted .dll file and execute arbitrary code on the target system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Symantec Endpoint Protection: 14.2 RU1 - 14.2 RU2

Symantec Endpoint Protection Small Business Edition: 14.0.1904.0000 - 14.2.5323.2000


CPE

External links
http://support.symantec.com/us/en/article.SYMSA1505.html


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability