First published: Thu Apr 25 2019(Updated: )
Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Endpoint Protection Manager | =12.1-rtm | |
Symantec Endpoint Protection Manager | =12.1-ru1 | |
Symantec Endpoint Protection Manager | =12.1-ru1-mp1 | |
Symantec Endpoint Protection Manager | =12.1-ru2 | |
Symantec Endpoint Protection Manager | =12.1-ru2-mp1 | |
Symantec Endpoint Protection Manager | =12.1-ru3 | |
Symantec Endpoint Protection Manager | =12.1-ru4 | |
Symantec Endpoint Protection Manager | =12.1-ru4-mp1 | |
Symantec Endpoint Protection Manager | =12.1-ru4-mp1a | |
Symantec Endpoint Protection Manager | =12.1-ru4-mp1b | |
Symantec Endpoint Protection Manager | =12.1-ru4a | |
Symantec Endpoint Protection Manager | =12.1-ru5 | |
Symantec Endpoint Protection Manager | =12.1-ru6 | |
Symantec Endpoint Protection Manager | =12.1-ru6-mp1 | |
Symantec Endpoint Protection Manager | =12.1-ru6-mp1a | |
Symantec Endpoint Protection Manager | =12.1-ru6-mp2 | |
Symantec Endpoint Protection Manager | =12.1-ru6-mp3 | |
Symantec Endpoint Protection Manager | =12.1-ru6-mp4 | |
Symantec Endpoint Protection Manager | =12.1-ru6-mp5 | |
Symantec Endpoint Protection Manager | =12.1-ru6-mp6 | |
Symantec Endpoint Protection Manager | =12.1-ru6-mp7 | |
Symantec Endpoint Protection Manager | =12.1-ru6-mp8 | |
Symantec Endpoint Protection Manager | =12.1-ru6-mp9 | |
Symantec Endpoint Protection Manager | =14 | |
Symantec Endpoint Protection Manager | =14-mp1 | |
Symantec Endpoint Protection Manager | =14-mp2 | |
Symantec Endpoint Protection Manager | =14.0.1 | |
Symantec Endpoint Protection Manager | =14.0.1-mp1 | |
Symantec Endpoint Protection Manager | =14.0.1-mp2 | |
Symantec Endpoint Protection Manager | =14.1 | |
Symantec Endpoint Protection Manager | =14.2 | |
Symantec Endpoint Protection Manager | =14.2-mp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-18367.
CVE-2018-18367 has a severity level of 7.8 (High).
The affected software is Symantec Endpoint Protection Manager (SEPM) versions prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1.
CVE-2018-18367 is a DLL Preloading vulnerability.
To fix CVE-2018-18367, update Symantec Endpoint Protection Manager to version 12.1 RU6 MP10 or 14.2 RU1.