CVE-2015-6556: Infoleak
Published Dec 18, 2015
·Updated
EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows remote authenticated users to discover credentials by triggering a memory dump.
Affected Software
1 affected component
Symantec Endpoint Encryption<=11.0
Event History
Dec 18, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6556?
CVE-2015-6556 is considered a medium severity vulnerability due to its potential to expose sensitive credentials.
2
How do I fix CVE-2015-6556?
To fix CVE-2015-6556, upgrade Symantec Endpoint Encryption to version 11.1.0 or later.
3
Who is affected by CVE-2015-6556?
CVE-2015-6556 affects users of Symantec Endpoint Encryption versions prior to 11.1.0.
4
What type of attack vector does CVE-2015-6556 allow?
CVE-2015-6556 allows remote authenticated users to exploit the vulnerability to trigger a memory dump and discover credentials.
5
Is there a workaround for CVE-2015-6556?
There is no official workaround for CVE-2015-6556; updating to a secure version is the recommended solution.