CVE-2018-12244: Medium severity symantec endpoint protection vulnerability

Published Apr 25, 2019
·
Updated

SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.

Affected Software

48 affected components
Symantec Endpoint Protection Macos=11.0
Symantec Endpoint Protection Macos=11.0-mr1
Symantec Endpoint Protection Macos=11.0-mr2
Symantec Endpoint Protection Macos=11.0-mr3
Symantec Endpoint Protection Macos=11.0-mr4
Symantec Endpoint Protection Macos=11.0-mr4-mp2
Symantec Endpoint Protection Macos=11.0-ru5
Symantec Endpoint Protection Macos=11.0-ru6
Symantec Endpoint Protection Macos=11.0-ru6-mp1
Symantec Endpoint Protection Macos=11.0-ru6-mp2
Symantec Endpoint Protection Macos=11.0-ru6-mp3
Symantec Endpoint Protection Macos=11.0-ru6a
Symantec Endpoint Protection Macos=11.0-ru7
Symantec Endpoint Protection Macos=11.0-ru7-mp1
Symantec Endpoint Protection Macos=11.0-ru7-mp2
Symantec Endpoint Protection Macos=11.0-ru7-mp4
Symantec Endpoint Protection Macos=11.0-ru7-mp4a
Symantec Endpoint Protection Macos=11.0-ry7-mp3
Symantec Endpoint Protection Macos=12.1
Symantec Endpoint Protection Macos=12.1-ru1
Symantec Endpoint Protection Macos=12.1-ru1-mp1
Symantec Endpoint Protection Macos=12.1-ru2
Symantec Endpoint Protection Macos=12.1-ru2-mp1
Symantec Endpoint Protection Macos=12.1-ru3
Symantec Endpoint Protection Macos=12.1-ru4
Symantec Endpoint Protection Macos=12.1-ru4-mp1
Symantec Endpoint Protection Macos=12.1-ru4-mp1a
Symantec Endpoint Protection Macos=12.1-ru4-mp1b
Symantec Endpoint Protection Macos=12.1-ru4a
Symantec Endpoint Protection Macos=12.1-ru5
Symantec Endpoint Protection Macos=12.1-ru6
Symantec Endpoint Protection Mac Os X=12.1-ru6-mp1
Symantec Endpoint Protection Macos=12.1-ru6-mp10
Symantec Endpoint Protection Macos=12.1-ru6-mp2
Symantec Endpoint Protection Mac Os X=12.1-ru6-mp3
Symantec Endpoint Protection Macos=12.1-ru6-mp4
Symantec Endpoint Protection Mac Os X=12.1-ru6-mp5
Symantec Endpoint Protection Macos=12.1-ru6-mp6
Symantec Endpoint Protection Macos=12.1-ru6-mp7
Symantec Endpoint Protection Macos=12.1-ru6-mp8
Symantec Endpoint Protection Macos=14
Symantec Endpoint Protection Macos=14-mp1
Symantec Endpoint Protection Macos=14.0.0-mp2
Symantec Endpoint Protection Macos=14.0.1
Symantec Endpoint Protection Macos=14.0.1-mp1
Symantec Endpoint Protection Macos=14.0.1-mp2
Symantec Endpoint Protection Macos=14.2
Symantec Endpoint Protection Macos=14.2-mp1

Event History

Apr 25, 2019
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID for this issue?

The vulnerability ID for this issue is CVE-2018-12244.

2

What is the severity of CVE-2018-12244?

The severity of CVE-2018-12244 is medium (6.3).

3

Which versions of Symantec Endpoint Protection are affected by CVE-2018-12244?

Symantec Endpoint Protection versions prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 are affected by CVE-2018-12244.

4

What is the vulnerability description of CVE-2018-12244?

CVE-2018-12244 is a CSV/DDE injection vulnerability in the SEP (Mac client) that allows untrusted input into CSV files.

5

How can I fix CVE-2018-12244?

To fix CVE-2018-12244, update your Symantec Endpoint Protection to version 12.1 RU6 MP10 or 14.2 MP1 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203