CVE-2017-6331

HIGH

Symantec Endpoint Protection <SEP 14 RU1 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-6331. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This exploit demonstrates a tamper-protection bypass in Symantec Endpoint Protection by spoofing WinAPI messages to manipulate the UI, including injecting arbitrary messages and closing windows to deny user access to AV scans.

Description

Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients.

Exploits (1)

exploitdb WORKING POC VERIFIED
by hyp3rlinx · clocalwindows
https://www.exploit-db.com/exploits/43134

This exploit demonstrates a tamper-protection bypass in Symantec Endpoint Protection by spoofing WinAPI messages to manipulate the UI, including injecting arbitrary messages and closing windows to deny user access to AV scans.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Symantec Endpoint Protection v12.1.6 (12.1 RU6 MP5) and Symantec 12.1.7004.6500
No auth needed
Prerequisites: Local access to the target system · Symantec Endpoint Protection running with vulnerable version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Issue Tracking, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43134/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101502
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039775

Scores

CVSS v3 7.1
EPSS 0.0169
EPSS Percentile 74.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Details

Status published
Products (2)
symantec/endpoint_protection < 14.0
Symantec Corporation/Symantec Endpoint Protection Prior to SEP 14 RU1
Published Nov 06, 2017
Tracked Since Feb 18, 2026