First published: Thu Apr 25 2019(Updated: )
Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Endpoint Protection | =nis-22.15.2.22 | |
Symantec Endpoint Protection | =sep-12.1.7484.7002 | |
Symantec Endpoint Protection Cloud | <22.16.3 | |
Symantec Endpoint Protection Cloud Agent | <3.00.31.2817 | |
Symantec Norton Security | <22.16.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-18369 is high with a CVSS score of 7.8.
Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002 are affected by CVE-2018-18369.
A DLL Preloading vulnerability is a type of issue that can occur when an application looks to call a DLL for execution, but the DLL is loaded from a location that is not secure.
To fix CVE-2018-18369, it is recommended to update Norton Security to version 22.16.3 or later and SEP SBE to Cloud Agent 3.00.31.2817 or later.
More information about CVE-2018-18369 can be found at the following references: [1] http://www.securityfocus.com/bid/107997 [2] https://support.symantec.com/en_US/article.SYMSA1479.html