CVE-2016-9092: CSRF
The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote attacker can use phishing or other social engineering techniques to access the management console with the privileges of an authenticated administrator user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9092?
CVE-2016-9092 is classified as a medium severity vulnerability.
How do I fix CVE-2016-9092?
To remediate CVE-2016-9092, upgrade your Symantec Content Analysis to version 2.2.1.1 or later and Mail Threat Defense to a protected version.
What systems are affected by CVE-2016-9092?
CVE-2016-9092 affects Symantec Content Analysis versions 1.3 and 2.x prior to 2.2.1.1, as well as Mail Threat Defense version 1.1.
Can CVE-2016-9092 be exploited remotely?
Yes, CVE-2016-9092 can be exploited remotely through cross-site request forgery techniques.
Is user interaction required for exploiting CVE-2016-9092?
Yes, exploiting CVE-2016-9092 typically requires user interaction via phishing or social engineering.