CVE-2018-18366: Medium severity symantec endpoint protection vulnerability

Published Apr 25, 2019
·
Updated

Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can cause the driver to return uninitialized memory.

Affected Software

53 affected components
Symantec Endpoint Protection Windows=11.0
Symantec Endpoint Protection Windows=11.0-mr1
Symantec Endpoint Protection Windows=11.0-mr2
Symantec Endpoint Protection Windows=11.0-mr3
Symantec Endpoint Protection Windows=11.0-mr4
Symantec Endpoint Protection Windows=11.0-mr4-mp2
Symantec Endpoint Protection Windows=11.0-ru5
Symantec Endpoint Protection Windows=11.0-ru6
Symantec Endpoint Protection Windows=11.0-ru6-mp1
Symantec Endpoint Protection Windows=11.0-ru6-mp2
Symantec Endpoint Protection Windows=11.0-ru6-mp3
Symantec Endpoint Protection Windows=11.0-ru6a
Symantec Endpoint Protection Windows=11.0-ru7
Symantec Endpoint Protection Windows=11.0-ru7-mp1
Symantec Endpoint Protection Windows=11.0-ru7-mp2
Symantec Endpoint Protection Windows=11.0-ru7-mp4
Symantec Endpoint Protection Windows=11.0-ru7-mp4a
Symantec Endpoint Protection Windows=11.0-ry7-mp3
Symantec Endpoint Protection Windows=12.1
Symantec Endpoint Protection Windows=12.1-ru1
Symantec Endpoint Protection Windows=12.1-ru1-mp1
Symantec Endpoint Protection Windows=12.1-ru2
Symantec Endpoint Protection Windows=12.1-ru2-mp1
Symantec Endpoint Protection Windows=12.1-ru3
Symantec Endpoint Protection Windows=12.1-ru4
Symantec Endpoint Protection Windows=12.1-ru4-mp1
Symantec Endpoint Protection Windows=12.1-ru4-mp1a
Symantec Endpoint Protection Windows=12.1-ru4-mp1b
Symantec Endpoint Protection Windows=12.1-ru4a
Symantec Endpoint Protection Windows=12.1-ru5
Symantec Endpoint Protection Windows=12.1-ru6
Symantec Endpoint Protection Windows=12.1-ru6-mp1
Symantec Endpoint Protection Windows=12.1-ru6-mp10
Symantec Endpoint Protection Windows=12.1-ru6-mp2
Symantec Endpoint Protection Windows=12.1-ru6-mp3
Symantec Endpoint Protection Windows=12.1-ru6-mp4
Symantec Endpoint Protection Windows=12.1-ru6-mp5
Symantec Endpoint Protection Windows=12.1-ru6-mp6
Symantec Endpoint Protection Windows=12.1-ru6-mp7
Symantec Endpoint Protection Windows=12.1-ru6-mp8
Symantec Endpoint Protection Windows=14
Symantec Endpoint Protection Windows=14-mp1
Symantec Endpoint Protection Windows=14.0.0-mp2
Symantec Endpoint Protection Windows=14.0.1
Symantec Endpoint Protection Windows=14.0.1-mp1
Symantec Endpoint Protection Windows=14.0.1-mp2
Symantec Endpoint Protection Windows=14.2
Symantec Endpoint Protection Windows=14.2-mp1
Symantec Endpoint Protection=nis-22.15.2.22
Symantec Endpoint Protection=sep-12.1.7484.7002
Symantec Endpoint Protection Cloud<22.16.3
Symantec Endpoint Protection Cloud Agent<3.00.31.2817
Symantec Norton Security Windows<22.16.3

Event History

Apr 25, 2019
CVE Published
via MITRE·07:13 PM
Data Sourced
via MITRE·07:13 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-18366?

CVE-2018-18366 has been classified with a medium severity rating due to its potential impact on kernel memory disclosure.

2

How do I fix CVE-2018-18366?

To remediate CVE-2018-18366, update to Symantec Norton Security version 22.16.3 or higher, and ensure SEP versions are at least 12.1 RU7 or 14.2 RU1.

3

Which software is affected by CVE-2018-18366?

CVE-2018-18366 affects Symantec Norton Security, various versions of Symantec Endpoint Protection, and specific releases of SEP Cloud and SEP SBE.

4

What are the potential risks of CVE-2018-18366?

The risks associated with CVE-2018-18366 include unauthorized access to sensitive kernel memory, which could lead to further exploitation.

5

Is there a workaround for CVE-2018-18366?

Currently, there are no known workarounds for CVE-2018-18366 other than applying the recommended updates to affected Symantec products.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203