CVE-2017-6331
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 1.69% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- symantec/endpoint protection
- Source
- secure@symantec.com
References
- http://www.securityfocus.com/bid/101502Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039775Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43134/Exploit, Issue Tracking, Third Party Advisory, VDB Entry
- https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20171106_00Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/101502Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039775Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43134/Exploit, Issue Tracking, Third Party Advisory, VDB Entry
- https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20171106_00Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.