CVE-2015-1492: Input Validation
Published Aug 1, 2015
·Updated
Untrusted search path vulnerability in the client in Symantec Endpoint Protection 12.1 before 12.1-RU6-MP1 allows local users to gain privileges via a Trojan horse DLL in a client install package.
Affected Software
1 affected component
Symantec Endpoint Protection Manager=12.1.0
Event History
Aug 1, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1492?
CVE-2015-1492 has a medium severity rating due to the potential for local privilege escalation.
2
How do I fix CVE-2015-1492?
To fix CVE-2015-1492, upgrade your Symantec Endpoint Protection to version 12.1-RU6-MP1 or later.
3
What type of vulnerability is CVE-2015-1492?
CVE-2015-1492 is classified as an untrusted search path vulnerability.
4
Who can exploit CVE-2015-1492?
Local users can exploit CVE-2015-1492 to gain elevated privileges on affected systems.
5
What software is affected by CVE-2015-1492?
CVE-2015-1492 affects Symantec Endpoint Protection version 12.1.0 prior to 12.1-RU6-MP1.