Symantec Endpoint Protection Client < 12.1 RU4 MP1b (SYM14-013)

medium Nessus Plugin ID 77050

Synopsis

The version of Symantec Endpoint Protection Client installed on the remote host is affected by a local privilege escalation vulnerability.

Description

The version of Symantec Endpoint Protection Client running on the remote host is either 11.x or 12.x prior to 12.1 RU4 MP1b. It is, therefore, affected by a local privilege escalation vulnerability.

A flaw exists in the sysplant driver due to insufficient validation of external input. An attacker, using specially crafted IOCTL code, could cause a kernel pool overflow resulting in elevated privileges to SYSTEM.

Solution

Upgrade to version 12.1 RU4 MP1b (12.1.4112.4156) or later.

See Also

http://www.nessus.org/u?1de9bbfe

http://www.nessus.org/u?74aa12c5

Plugin Details

Severity: Medium

ID: 77050

File Name: symantec_endpoint_prot_client_sym14-013.nasl

Version: 1.13

Type: local

Agent: windows

Family: Windows

Published: 8/7/2014

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.9

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Temporal Score: 6

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:symantec:endpoint_protection

Required KB Items: Antivirus/SAVCE/version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/4/2014

Vulnerability Publication Date: 7/29/2014

Exploitable With

Core Impact

Reference Information

CVE: CVE-2014-3434

BID: 68946

CERT: 252068