CVE-2012-0294: Path Traversal
Published May 23, 2012
·Updated
Directory traversal vulnerability in the Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to delete files via unspecified vectors.
Affected Software
3 affected components
Symantec Endpoint Protection=12.1
Symantec Endpoint Protection=12.1.671
Symantec Endpoint Protection=12.1.1000
Event History
May 23, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0294?
CVE-2012-0294 is classified as a high severity vulnerability due to its potential for remote file deletion.
2
How do I fix CVE-2012-0294?
To fix CVE-2012-0294, upgrade Symantec Endpoint Protection to version 12.1 RU1-MP1 or later.
3
What systems are affected by CVE-2012-0294?
CVE-2012-0294 affects Symantec Endpoint Protection versions prior to 12.1 RU1-MP1.
4
Can CVE-2012-0294 be exploited remotely?
Yes, CVE-2012-0294 can be exploited remotely by attackers to delete files.
5
Is there a workaround for CVE-2012-0294?
There are no documented workarounds for CVE-2012-0294; updating the software is the recommended action.