CVE-2020-5837
HIGHSymantec Endpoint Protection <14.3 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-5837. PoCs published by RedyOpsResearchLabs.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2020-5837, targeting Symantec Endpoint Protection (SEP) 14.2. The exploit leverages arbitrary write vulnerabilities via symbolic link manipulation, based on James Forshaw's symboliclink-testing-tools.
Description
Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.
Exploits (1)
This repository contains a functional exploit for CVE-2020-5837, targeting Symantec Endpoint Protection (SEP) 14.2. The exploit leverages arbitrary write vulnerabilities via symbolic link manipulation, based on James Forshaw's symboliclink-testing-tools.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H