CVE-2018-18366: Medium severity symantec endpoint protection vulnerability
Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can cause the driver to return uninitialized memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18366?
CVE-2018-18366 has been classified with a medium severity rating due to its potential impact on kernel memory disclosure.
How do I fix CVE-2018-18366?
To remediate CVE-2018-18366, update to Symantec Norton Security version 22.16.3 or higher, and ensure SEP versions are at least 12.1 RU7 or 14.2 RU1.
Which software is affected by CVE-2018-18366?
CVE-2018-18366 affects Symantec Norton Security, various versions of Symantec Endpoint Protection, and specific releases of SEP Cloud and SEP SBE.
What are the potential risks of CVE-2018-18366?
The risks associated with CVE-2018-18366 include unauthorized access to sensitive kernel memory, which could lead to further exploitation.
Is there a workaround for CVE-2018-18366?
Currently, there are no known workarounds for CVE-2018-18366 other than applying the recommended updates to affected Symantec products.