CVE-2018-12245

HIGH

Symantec Endpoint Protection <14.2 MP1 - DLL Preloading

Title source: llm
STIX 2.1

Description

Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case is an issue that can occur when an application being installed unintentionally loads a DLL provided by a potential attacker. Note that this particular type of exploit only manifests at install time; no remediation is required for software that has already been installed. This issue only impacted the Trialware media for Symantec Endpoint Protection, which has since been updated.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105919

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 46.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (1)
symantec/endpoint_protection 11.0 - 14.2.0.1
Published Nov 29, 2018
Tracked Since Feb 18, 2026