First published: Mon May 11 2020(Updated: )
Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Endpoint Protection | <14.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5837 is a vulnerability in Symantec Endpoint Protection prior to 14.3 that may not respect file permissions when writing to log files that are replaced by symbolic links, leading to a potential elevation of privilege.
CVE-2020-5837 can lead to a potential elevation of privilege in Symantec Endpoint Protection prior to version 14.3.
CVE-2020-5837 has a severity rating of 7.8 (High).
To fix CVE-2020-5837 in Symantec Endpoint Protection, you should update to version 14.3 or later.
You can find more information about CVE-2020-5837 in the Symantec Endpoint Protection Security Advisory at https://support.broadcom.com/security-advisory/security-advisory-detail.html?notificationId=SYMSA1762