CVE-2017-6331
HIGHSymantec Endpoint Protection <SEP 14 RU1 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-6331. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates a tamper-protection bypass in Symantec Endpoint Protection by spoofing WinAPI messages to manipulate the UI, including injecting arbitrary messages and closing windows to deny user access to AV scans.
Description
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients.
Exploits (1)
This exploit demonstrates a tamper-protection bypass in Symantec Endpoint Protection by spoofing WinAPI messages to manipulate the UI, including injecting arbitrary messages and closing windows to deny user access to AV scans.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H