CVE-2013-5011: Path Traversal
Unquoted Windows search path vulnerability in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 allows local users to gain privileges via a crafted program in the %SYSTEMDRIVE% directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5011?
CVE-2013-5011 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2013-5011?
To mitigate CVE-2013-5011, upgrade Symantec Endpoint Protection to version 11.0.7.4 or later for the 11.x series and to 12.1.2 RU2 or later for the 12.x series.
Who is affected by CVE-2013-5011?
CVE-2013-5011 affects versions of Symantec Endpoint Protection 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2.
What type of vulnerability is CVE-2013-5011?
CVE-2013-5011 is classified as an unquoted Windows search path vulnerability.
Can CVE-2013-5011 be exploited remotely?
CVE-2013-5011 requires local access for exploitation, as it allows local users to gain privileges.