Unquoted Windows search path vulnerability in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 allows local users to gain privileges via a crafted program in the %SYSTEMDRIVE% directory.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-01-10 08:47
Updated : 2017-08-28 18:33
NVD link : CVE-2013-5011
Mitre link : CVE-2013-5011
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
symantec
- endpoint_protection