CVE-2012-4348: Input Validation
The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly validate input for PHP scripts, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4348?
CVE-2012-4348 is classified as a critical vulnerability that allows remote authenticated users to execute arbitrary code.
How do I fix CVE-2012-4348?
To fix CVE-2012-4348, upgrade Symantec Endpoint Protection to version 11.0 RU7-MP3 or 12.1 RU2 or later.
Which versions of Symantec Endpoint Protection are affected by CVE-2012-4348?
CVE-2012-4348 affects Symantec Endpoint Protection versions 11.0 prior to RU7-MP3, 12.1 prior to RU2, and 12.x prior to 12.1 RU2.
Can CVE-2012-4348 be exploited without authentication?
No, CVE-2012-4348 can only be exploited by authenticated users.
What type of vulnerability is CVE-2012-4348?
CVE-2012-4348 is an input validation vulnerability in the management console of Symantec Endpoint Protection.