CVE-2014-3439

Symantec Endpoint Protection Manager <12.1 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-3439. PoCs published by SEC Consult.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Symantec Endpoint Protection, including XXE for file disclosure and SSRF, XSS for session hijacking, and arbitrary file write/overwrite for DoS or potential code execution. The PoC includes detailed steps and code snippets for each vulnerability.

Description

ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vectors.

Exploits (1)

exploitdb WORKING POC
by SEC Consult · textwebappsjsp
https://www.exploit-db.com/exploits/35181

The exploit demonstrates multiple vulnerabilities in Symantec Endpoint Protection, including XXE for file disclosure and SSRF, XSS for session hijacking, and arbitrary file write/overwrite for DoS or potential code execution. The PoC includes detailed steps and code snippets for each vulnerability.

Classification
Working Poc 100%
Attack Type
Xxe | Xss | Dos | Info Leak | Ssrf
Complexity
Moderate
Reliability
Reliable
Target: Symantec Endpoint Protection 12.1.4023.4080
No auth needed
Prerequisites: Network access to the target · Ability to intercept/modify traffic (for XXE) · Ability to send crafted HTTP requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Nov/7
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70845
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98527
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533918/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031176

Scores

EPSS 0.0584
EPSS Percentile 92.2%

Details

Status published
Products (5)
symantec/endpoint_protection_manager 12.1.0
symantec/endpoint_protection_manager 12.1.1
symantec/endpoint_protection_manager 12.1.2
symantec/endpoint_protection_manager 12.1.3
symantec/endpoint_protection_manager < 12.1.4
Published Nov 07, 2014
Tracked Since Feb 18, 2026