CVE-2018-12244: Medium severity symantec endpoint protection vulnerability
Published Apr 25, 2019
·Updated
SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.
Affected Software
48 affected components
Symantec Endpoint Protection Macos=11.0
Symantec Endpoint Protection Macos=11.0-mr1
Symantec Endpoint Protection Macos=11.0-mr2
Symantec Endpoint Protection Macos=11.0-mr3
Symantec Endpoint Protection Macos=11.0-mr4
Symantec Endpoint Protection Macos=11.0-mr4-mp2
Symantec Endpoint Protection Macos=11.0-ru5
Symantec Endpoint Protection Macos=11.0-ru6
Symantec Endpoint Protection Macos=11.0-ru6-mp1
Symantec Endpoint Protection Macos=11.0-ru6-mp2
Symantec Endpoint Protection Macos=11.0-ru6-mp3
Symantec Endpoint Protection Macos=11.0-ru6a
Symantec Endpoint Protection Macos=11.0-ru7
Symantec Endpoint Protection Macos=11.0-ru7-mp1
Symantec Endpoint Protection Macos=11.0-ru7-mp2
Symantec Endpoint Protection Macos=11.0-ru7-mp4
Symantec Endpoint Protection Macos=11.0-ru7-mp4a
Symantec Endpoint Protection Macos=11.0-ry7-mp3
Symantec Endpoint Protection Macos=12.1
Symantec Endpoint Protection Macos=12.1-ru1
Symantec Endpoint Protection Macos=12.1-ru1-mp1
Symantec Endpoint Protection Macos=12.1-ru2
Symantec Endpoint Protection Macos=12.1-ru2-mp1
Symantec Endpoint Protection Macos=12.1-ru3
Symantec Endpoint Protection Macos=12.1-ru4
Symantec Endpoint Protection Macos=12.1-ru4-mp1
Symantec Endpoint Protection Macos=12.1-ru4-mp1a
Symantec Endpoint Protection Macos=12.1-ru4-mp1b
Symantec Endpoint Protection Macos=12.1-ru4a
Symantec Endpoint Protection Macos=12.1-ru5
Symantec Endpoint Protection Macos=12.1-ru6
Symantec Endpoint Protection Mac Os X=12.1-ru6-mp1
Symantec Endpoint Protection Macos=12.1-ru6-mp10
Symantec Endpoint Protection Macos=12.1-ru6-mp2
Symantec Endpoint Protection Mac Os X=12.1-ru6-mp3
Symantec Endpoint Protection Macos=12.1-ru6-mp4
Symantec Endpoint Protection Mac Os X=12.1-ru6-mp5
Symantec Endpoint Protection Macos=12.1-ru6-mp6
Symantec Endpoint Protection Macos=12.1-ru6-mp7
Symantec Endpoint Protection Macos=12.1-ru6-mp8
Symantec Endpoint Protection Macos=14
Symantec Endpoint Protection Macos=14-mp1
Symantec Endpoint Protection Macos=14.0.0-mp2
Symantec Endpoint Protection Macos=14.0.1
Symantec Endpoint Protection Macos=14.0.1-mp1
Symantec Endpoint Protection Macos=14.0.1-mp2
Symantec Endpoint Protection Macos=14.2
Symantec Endpoint Protection Macos=14.2-mp1
Event History
Apr 25, 2019
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-12244.
2
What is the severity of CVE-2018-12244?
The severity of CVE-2018-12244 is medium (6.3).
3
Which versions of Symantec Endpoint Protection are affected by CVE-2018-12244?
Symantec Endpoint Protection versions prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 are affected by CVE-2018-12244.
4
What is the vulnerability description of CVE-2018-12244?
CVE-2018-12244 is a CSV/DDE injection vulnerability in the SEP (Mac client) that allows untrusted input into CSV files.
5
How can I fix CVE-2018-12244?
To fix CVE-2018-12244, update your Symantec Endpoint Protection to version 12.1 RU6 MP10 or 14.2 MP1 or later.