First published: Thu Apr 25 2019(Updated: )
SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Endpoint Protection | =11.0 | |
Symantec Endpoint Protection | =11.0-mr1 | |
Symantec Endpoint Protection | =11.0-mr2 | |
Symantec Endpoint Protection | =11.0-mr3 | |
Symantec Endpoint Protection | =11.0-mr4 | |
Symantec Endpoint Protection | =11.0-mr4-mp2 | |
Symantec Endpoint Protection | =11.0-ru5 | |
Symantec Endpoint Protection | =11.0-ru6 | |
Symantec Endpoint Protection | =11.0-ru6-mp1 | |
Symantec Endpoint Protection | =11.0-ru6-mp2 | |
Symantec Endpoint Protection | =11.0-ru6-mp3 | |
Symantec Endpoint Protection | =11.0-ru6a | |
Symantec Endpoint Protection | =11.0-ru7 | |
Symantec Endpoint Protection | =11.0-ru7-mp1 | |
Symantec Endpoint Protection | =11.0-ru7-mp2 | |
Symantec Endpoint Protection | =11.0-ru7-mp4 | |
Symantec Endpoint Protection | =11.0-ru7-mp4a | |
Symantec Endpoint Protection | =11.0-ry7-mp3 | |
Symantec Endpoint Protection | =12.1 | |
Symantec Endpoint Protection | =12.1-ru1 | |
Symantec Endpoint Protection | =12.1-ru1-mp1 | |
Symantec Endpoint Protection | =12.1-ru2 | |
Symantec Endpoint Protection | =12.1-ru2-mp1 | |
Symantec Endpoint Protection | =12.1-ru3 | |
Symantec Endpoint Protection | =12.1-ru4 | |
Symantec Endpoint Protection | =12.1-ru4-mp1 | |
Symantec Endpoint Protection | =12.1-ru4-mp1a | |
Symantec Endpoint Protection | =12.1-ru4-mp1b | |
Symantec Endpoint Protection | =12.1-ru4a | |
Symantec Endpoint Protection | =12.1-ru5 | |
Symantec Endpoint Protection | =12.1-ru6 | |
Symantec Endpoint Protection | =12.1-ru6-mp1 | |
Symantec Endpoint Protection | =12.1-ru6-mp10 | |
Symantec Endpoint Protection | =12.1-ru6-mp2 | |
Symantec Endpoint Protection | =12.1-ru6-mp3 | |
Symantec Endpoint Protection | =12.1-ru6-mp4 | |
Symantec Endpoint Protection | =12.1-ru6-mp5 | |
Symantec Endpoint Protection | =12.1-ru6-mp6 | |
Symantec Endpoint Protection | =12.1-ru6-mp7 | |
Symantec Endpoint Protection | =12.1-ru6-mp8 | |
Symantec Endpoint Protection | =14 | |
Symantec Endpoint Protection | =14-mp1 | |
Symantec Endpoint Protection | =14.0.0-mp2 | |
Symantec Endpoint Protection | =14.0.1 | |
Symantec Endpoint Protection | =14.0.1-mp1 | |
Symantec Endpoint Protection | =14.0.1-mp2 | |
Symantec Endpoint Protection | =14.2 | |
Symantec Endpoint Protection | =14.2-mp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-12244.
The severity of CVE-2018-12244 is medium (6.3).
Symantec Endpoint Protection versions prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 are affected by CVE-2018-12244.
CVE-2018-12244 is a CSV/DDE injection vulnerability in the SEP (Mac client) that allows untrusted input into CSV files.
To fix CVE-2018-12244, update your Symantec Endpoint Protection to version 12.1 RU6 MP10 or 14.2 MP1 or later.