CVE-2012-0295: Code Injection
Published May 23, 2012
·Updated
The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294.
Affected Software
3 affected components
Symantec Endpoint Protection=12.1
Symantec Endpoint Protection=12.1.671
Symantec Endpoint Protection=12.1.1000
Event History
May 23, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0295?
CVE-2012-0295 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2012-0295?
To mitigate CVE-2012-0295, update Symantec Endpoint Protection to version 12.1 RU1-MP1 or later.
3
What types of systems are affected by CVE-2012-0295?
CVE-2012-0295 affects Symantec Endpoint Protection versions 12.1, 12.1.671, and 12.1.1000.
4
Can CVE-2012-0295 be exploited remotely?
Yes, CVE-2012-0295 can be exploited remotely by attackers through file-insertion methods.
5
What is the impact of exploiting CVE-2012-0295?
Exploiting CVE-2012-0295 can lead to unauthorized code execution on vulnerable systems.