First published: Fri Jan 10 2014(Updated: )
Unquoted Windows search path vulnerability in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 allows local users to gain privileges via a crafted program in the %SYSTEMDRIVE% directory.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Endpoint Protection | <=11.0.7.3 | |
Symantec Endpoint Protection | =11.0 | |
Symantec Endpoint Protection | =11.0-ru5 | |
Symantec Endpoint Protection | =11.0-ru6 | |
Symantec Endpoint Protection | =11.0-ru6a | |
Symantec Endpoint Protection | =11.0-ru6mp1 | |
Symantec Endpoint Protection | =11.0-ru6mp2 | |
Symantec Endpoint Protection | =11.0.1 | |
Symantec Endpoint Protection | =11.0.1-mp1 | |
Symantec Endpoint Protection | =11.0.1-mp2 | |
Symantec Endpoint Protection | =11.0.2 | |
Symantec Endpoint Protection | =11.0.2-mp1 | |
Symantec Endpoint Protection | =11.0.2-mp2 | |
Symantec Endpoint Protection | =11.0.4 | |
Symantec Endpoint Protection | =11.0.4-mp1a | |
Symantec Endpoint Protection | =11.0.4-mp2 | |
Symantec Endpoint Protection | =11.0.3001 | |
Symantec Endpoint Protection | =11.0.6000 | |
Symantec Endpoint Protection | =11.0.6100 | |
Symantec Endpoint Protection | =11.0.6200 | |
Symantec Endpoint Protection | =11.0.6200.754 | |
Symantec Endpoint Protection | =11.0.6300 | |
Symantec Endpoint Protection | =11.0.7000 | |
Symantec Endpoint Protection | =11.0.7100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5011 has a medium severity rating due to its potential for local privilege escalation.
To mitigate CVE-2013-5011, upgrade Symantec Endpoint Protection to version 11.0.7.4 or later for the 11.x series and to 12.1.2 RU2 or later for the 12.x series.
CVE-2013-5011 affects versions of Symantec Endpoint Protection 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2.
CVE-2013-5011 is classified as an unquoted Windows search path vulnerability.
CVE-2013-5011 requires local access for exploitation, as it allows local users to gain privileges.