CVE-2015-1486
Symantec Endpoint Protection Manager <12.1-RU6-MP1 - Auth Bypass
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2015-1486.
PoCs published by Metasploit, Markus Wulftange, bperry, including Metasploit module exploits/windows/http/sepm_auth_bypass_rce.
AI-analyzed exploit summary This Metasploit module exploits CVE-2015-1489 (alongside CVE-2015-1486 and CVE-2015-1487) to achieve remote code execution on Symantec Endpoint Protection Manager by chaining an authentication bypass, directory traversal, and privilege escalation to execute a payload as NT AUTHORITY\SYSTEM.
Description
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session.
Exploits (2)
This Metasploit module exploits CVE-2015-1489 (alongside CVE-2015-1486 and CVE-2015-1487) to achieve remote code execution on Symantec Endpoint Protection Manager by chaining an authentication bypass, directory traversal, and privilege escalation to execute a payload as NT AUTHORITY\SYSTEM.
This Metasploit module exploits three vulnerabilities in Symantec Endpoint Protection Manager (CVE-2015-1486, CVE-2015-1487, CVE-2015-1489) to achieve remote code execution as NT AUTHORITY\SYSTEM via authentication bypass, directory traversal, and privilege escalation.