First published: Tue Feb 11 2020(Updated: )
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Endpoint Protection | =11.0 | |
Symantec Endpoint Protection | =11.0-mr1 | |
Symantec Endpoint Protection | =11.0-mr2 | |
Symantec Endpoint Protection | =11.0-mr3 | |
Symantec Endpoint Protection | =11.0-mr4 | |
Symantec Endpoint Protection | =11.0-mr4-mp1a | |
Symantec Endpoint Protection | =11.0-mr4-mp2 | |
Symantec Endpoint Protection | =11.0-ru5 | |
Symantec Endpoint Protection | =11.0-ru6 | |
Symantec Endpoint Protection | =11.0-ru6-mp1 | |
Symantec Endpoint Protection | =11.0-ru6-mp2 | |
Symantec Endpoint Protection | =11.0-ru6-mp3 | |
Symantec Endpoint Protection | =11.0-ru6a | |
Symantec Endpoint Protection | =11.0-ru7 | |
Symantec Endpoint Protection | =11.0-ru7-mp1 | |
Symantec Endpoint Protection | =11.0-ru7-mp2 | |
Symantec Endpoint Protection | =11.0-ru7-mp3 | |
Symantec Endpoint Protection | =11.0-ru7-mp4 | |
Symantec Endpoint Protection | =11.0-ru7-mp4a | |
Symantec Endpoint Protection | =12.1 | |
Symantec Endpoint Protection | =12.1-ru1 | |
Symantec Endpoint Protection | =12.1-ru1-p1 | |
Symantec Endpoint Protection | =12.1-ru2 | |
Symantec Endpoint Protection | =12.1-ru2-mp1 | |
Symantec Endpoint Protection | =12.1-ru3 | |
Symantec Endpoint Protection | =12.1-ru4 | |
Symantec Endpoint Protection | =12.1-ru4-mp1 | |
Symantec Endpoint Protection | =12.1-ru4-mp1a | |
Symantec Endpoint Protection | =12.1-ru4-mp1b | |
Symantec Endpoint Protection | =12.1-ru4a | |
Symantec Endpoint Protection | =12.1-ru5 | |
Symantec Endpoint Protection | =12.1-ru6 | |
Symantec Endpoint Protection | =12.1-ru6-mp1 | |
Symantec Endpoint Protection | =12.1-ru6-mp2 | |
Symantec Endpoint Protection | =12.1-ru6-mp3 | |
Symantec Endpoint Protection | =12.1-ru6-mp4 | |
Symantec Endpoint Protection | =12.1-ru6-mp5 | |
Symantec Endpoint Protection | =12.1-ru6-mp6 | |
Symantec Endpoint Protection | =12.1-ru6-mp7 | |
Symantec Endpoint Protection | =12.1-ru6-mp8 | |
Symantec Endpoint Protection | =12.1-ru6-mp9 | |
Symantec Endpoint Protection | =14.0.0 | |
Symantec Endpoint Protection | =14.0.0-mp1 | |
Symantec Endpoint Protection | =14.0.0-mp2 | |
Symantec Endpoint Protection | =14.0.1 | |
Symantec Endpoint Protection | =14.0.1-mp1 | |
Symantec Endpoint Protection | =14.0.1-mp2 | |
Symantec Endpoint Protection | =14.2 | |
Symantec Endpoint Protection | =14.2-mp1 | |
Symantec Endpoint Protection | =14.2-ru1 | |
Symantec Endpoint Protection | =14.2-ru1_mp1 | |
Symantec Endpoint Protection | =14.2-ru2 | |
Symantec Endpoint Protection | =12.0-rtm | |
Symantec Endpoint Protection | =12.0-ru1 | |
Symantec Endpoint Protection | =12.1 | |
Symantec Endpoint Protection | =12.1-ru1 | |
Symantec Endpoint Protection | =12.1-ru1-mp1 | |
Symantec Endpoint Protection | =12.1-ru2 | |
Symantec Endpoint Protection | =12.1-ru2-mp1 | |
Symantec Endpoint Protection | =12.1-ru3 | |
Symantec Endpoint Protection | =12.1-ru4 | |
Symantec Endpoint Protection | =12.1-ru4-mp1 | |
Symantec Endpoint Protection | =12.1-ru4-mp1a | |
Symantec Endpoint Protection | =12.1-ru4-mp1b | |
Symantec Endpoint Protection | =12.1-ru4a | |
Symantec Endpoint Protection | =12.1-ru5 | |
Symantec Endpoint Protection | =12.1-ru6 | |
Symantec Endpoint Protection | =12.1-ru6_mp1 | |
Symantec Endpoint Protection | =12.1-ru6_mp10 | |
Symantec Endpoint Protection | =12.1-ru6_mp2 | |
Symantec Endpoint Protection | =12.1-ru6_mp3 | |
Symantec Endpoint Protection | =12.1-ru6_mp4 | |
Symantec Endpoint Protection | =12.1-ru6_mp5 | |
Symantec Endpoint Protection | =12.1-ru6_mp6 | |
Symantec Endpoint Protection | =12.1-ru6_mp7 | |
Symantec Endpoint Protection | =12.1-ru6_mp8 | |
Symantec Endpoint Protection | =12.1-ru6_mp9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5820 is classified as a privilege escalation vulnerability, which can potentially allow attackers to gain elevated access to system resources.
To mitigate CVE-2020-5820, you should upgrade to the latest versions of Symantec Endpoint Protection or Symantec Endpoint Protection Small Business Edition that are not affected.
CVE-2020-5820 affects Symantec Endpoint Protection versions prior to 14.2 RU2 MP1 and Symantec Endpoint Protection Small Business Edition versions prior to 14.2.5569.2100.
By exploiting CVE-2020-5820, an attacker may be able to elevate privileges and gain unauthorized access to sensitive system resources.
Currently, the recommendation is to apply the appropriate updates as there are no known workarounds for CVE-2020-5820.