CVE-2016-6590
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- symantec/encryption desktop · symantec/endpoint encryption · symantec/ghost solution suite · symantec/it management suite
- Source
- secure@symantec.com
References
- http://www.securityfocus.com/bid/94279Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037302Third Party Advisory, VDB Entry
- https://support.symantec.com/us/en/article.symsa1385.htmlVendor Advisory
- http://www.securityfocus.com/bid/94279Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037302Third Party Advisory, VDB Entry
- https://support.symantec.com/us/en/article.symsa1385.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.