CVE-2020-5825

MEDIUM

Symantec Endpoint Protection <14.2 RU2 MP1-<14.2.5569.2100 - Arbitr...

Title source: llm
STIX 2.1

Description

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an arbitrary file write vulnerability, which is a type of issue whereby an attacker is able to overwrite existing files on the resident system without proper privileges.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0009
EPSS Percentile 25.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (5)
symantec/endpoint_protection 11.0 (19 CPE variants)
symantec/endpoint_protection 12.1 (22 CPE variants)
symantec/endpoint_protection 14.0.0 (3 CPE variants)
symantec/endpoint_protection 14.0.1 (3 CPE variants)
symantec/endpoint_protection 14.2 (3 CPE variants)
Published Feb 11, 2020
Tracked Since Feb 18, 2026