CVE-2024-23617: Symantec Data Loss Prevention Buffer Overflow
Published Jan 25, 2024
·Updated
A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.
Affected Software
1 affected component
Broadcom Symantec Data Center Security Server<=14.0.2
Event History
Jan 25, 2024
CVE Published
via MITRE·11:32 PM
Data Sourced
via MITRE·11:32 PM
DescriptionSeverityWeakness
Jan 26, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23617?
CVE-2024-23617 has a high severity as it allows remote code execution through a buffer overflow vulnerability.
2
How do I fix CVE-2024-23617?
To fix CVE-2024-23617, upgrade Symantec Data Loss Prevention to version 14.0.3 or later.
3
Who is affected by CVE-2024-23617?
CVE-2024-23617 affects users of Symantec Data Loss Prevention version 14.0.2 and earlier.
4
What can an attacker achieve by exploiting CVE-2024-23617?
An attacker exploiting CVE-2024-23617 can achieve remote code execution on vulnerable systems.
5
What type of attack vector is associated with CVE-2024-23617?
CVE-2024-23617 can be exploited by enticing a user to open a specially crafted document.