First published: Fri Feb 08 2019(Updated: )
Symantec Ghost Solution Suite (GSS) versions prior to 3.3 RU1 may be susceptible to a DLL hijacking vulnerability, which is a type of issue whereby a potential attacker attempts to execute unexpected code on your machine. This occurs via placement of a potentially foreign file (DLL) that the attacker then attempts to run via a linked application.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Ghost Solution Suite | =2.0 | |
Symantec Ghost Solution Suite | =2.5 | |
Symantec Ghost Solution Suite | =3.0 | |
Symantec Ghost Solution Suite | =3.0-hf1 | |
Symantec Ghost Solution Suite | =3.0-hf2 | |
Symantec Ghost Solution Suite | =3.0-hf3 | |
Symantec Ghost Solution Suite | =3.0-hf4 | |
Symantec Ghost Solution Suite | =3.0-hf5 | |
Symantec Ghost Solution Suite | =3.1 | |
Symantec Ghost Solution Suite | =3.1-mp1 | |
Symantec Ghost Solution Suite | =3.1-mp2 | |
Symantec Ghost Solution Suite | =3.1-mp3 | |
Symantec Ghost Solution Suite | =3.1-mp4 | |
Symantec Ghost Solution Suite | =3.1-mp5 | |
Symantec Ghost Solution Suite | =3.1-mp6 | |
Symantec Ghost Solution Suite | =3.2 | |
Symantec Ghost Solution Suite | =3.2-ru1 | |
Symantec Ghost Solution Suite | =3.2-ru2 | |
Symantec Ghost Solution Suite | =3.2-ru3 | |
Symantec Ghost Solution Suite | =3.2-ru4 | |
Symantec Ghost Solution Suite | =3.2-ru5 | |
Symantec Ghost Solution Suite | =3.2-ru6 | |
Symantec Ghost Solution Suite | =3.2-ru7 | |
Symantec Ghost Solution Suite | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18364 is a DLL hijacking vulnerability in Symantec Ghost Solution Suite (GSS) versions prior to 3.3 RU1.
A DLL hijacking vulnerability occurs when a potentially foreign file (DLL) is placed on the machine by an attacker, allowing them to execute unexpected code.
Symantec Ghost Solution Suite versions 2.0 to 3.2 RU7 are affected by CVE-2018-18364.
The severity of CVE-2018-18364 is high, with a CVSS score of 7.3.
To fix CVE-2018-18364, upgrade to Symantec Ghost Solution Suite version 3.3 RU1 or later.