First published: Tue Dec 18 2012(Updated: )
The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly validate input for PHP scripts, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Endpoint Protection | =11.0 | |
Symantec Endpoint Protection | =11.0-ru5 | |
Symantec Endpoint Protection | =11.0-ru6 | |
Symantec Endpoint Protection | =11.0-ru6a | |
Symantec Endpoint Protection | =11.0-ru6mp1 | |
Symantec Endpoint Protection | =11.0-ru6mp2 | |
Symantec Endpoint Protection | =11.0.1 | |
Symantec Endpoint Protection | =11.0.1-mp1 | |
Symantec Endpoint Protection | =11.0.1-mp2 | |
Symantec Endpoint Protection | =11.0.2 | |
Symantec Endpoint Protection | =11.0.2-mp1 | |
Symantec Endpoint Protection | =11.0.2-mp2 | |
Symantec Endpoint Protection | =11.0.4 | |
Symantec Endpoint Protection | =11.0.4-mp1a | |
Symantec Endpoint Protection | =11.0.4-mp2 | |
Symantec Endpoint Protection | =11.0.3001 | |
Symantec Endpoint Protection | =11.0.6000 | |
Symantec Endpoint Protection | =11.0.6100 | |
Symantec Endpoint Protection | =11.0.6200 | |
Symantec Endpoint Protection | =11.0.6200.754 | |
Symantec Endpoint Protection | =11.0.6300 | |
Symantec Endpoint Protection | =11.0.7000 | |
Symantec Endpoint Protection | =11.0.7100 | |
Symantec Endpoint Protection | =12.1 | |
Symantec Endpoint Protection | =12.1.671 | |
Symantec Endpoint Protection | =12.1.1000 | |
Symantec Endpoint Protection | =12.0 | |
Symantec Endpoint Protection | =12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4348 is classified as a critical vulnerability that allows remote authenticated users to execute arbitrary code.
To fix CVE-2012-4348, upgrade Symantec Endpoint Protection to version 11.0 RU7-MP3 or 12.1 RU2 or later.
CVE-2012-4348 affects Symantec Endpoint Protection versions 11.0 prior to RU7-MP3, 12.1 prior to RU2, and 12.x prior to 12.1 RU2.
No, CVE-2012-4348 can only be exploited by authenticated users.
CVE-2012-4348 is an input validation vulnerability in the management console of Symantec Endpoint Protection.