CVE-2020-5821

HIGH

Symantec Endpoint Protection <14.2 RU2 MP1 - Code Injection

Title source: llm
STIX 2.1

Description

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a DLL injection vulnerability, which is a type of issue whereby an individual attempts to execute their own code in place of legitimate code as a means to perform an exploit.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0007
EPSS Percentile 21.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (5)
symantec/endpoint_protection 11.0 (19 CPE variants)
symantec/endpoint_protection 12.1 (22 CPE variants)
symantec/endpoint_protection 14.0.0 (3 CPE variants)
symantec/endpoint_protection 14.0.1 (3 CPE variants)
symantec/endpoint_protection 14.2 (3 CPE variants)
Published Feb 11, 2020
Tracked Since Feb 18, 2026