CVE-2017-15526: Null Pointer Dereference
Published Nov 13, 2017
·Updated
Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a null pointer de-reference issue, which can result in a NullPointerException that can lead to a privilege escalation scenario.
Affected Software
1 affected component
Symantec Endpoint Encryption<=11.1.3
Event History
Nov 13, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2017-15526?
CVE-2017-15526 is a vulnerability in Symantec Endpoint Encryption that can result in a privilege escalation scenario.
2
What is the severity of CVE-2017-15526?
The severity of CVE-2017-15526 is medium, with a score of 6.8.
3
How does CVE-2017-15526 affect Symantec Endpoint Encryption?
CVE-2017-15526 affects Symantec Endpoint Encryption versions prior to SEE v11.1.3MP1.
4
How can CVE-2017-15526 be exploited?
CVE-2017-15526 can be exploited through a null pointer de-reference issue, which can result in a NullPointerException.
5
Is there a fix for CVE-2017-15526?
Yes, the fix for CVE-2017-15526 is to upgrade to SEE v11.1.3MP1 or later.