Symantec Endpoint Protection Manager CVE-2014-3439 Arbitrary File Write Vulnerability
BID:70845
Info
Symantec Endpoint Protection Manager CVE-2014-3439 Arbitrary File Write Vulnerability
| Bugtraq ID: | 70845 |
| Class: | Design Error |
| CVE: |
CVE-2014-3439 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2014 12:00AM |
| Updated: | Nov 05 2014 12:00AM |
| Credit: | Stefan Viehböck with SEC Consult Vulnerability Lab |
| Vulnerable: |
Symantec Endpoint Protection Manager 12.1 RU4 Symantec Endpoint Protection Manager 12.1 RU3 Symantec Endpoint Protection Manager 12.1 RU2 Symantec Endpoint Protection Manager 12.1 |
| Not Vulnerable: |
Symantec Endpoint Protection Manager 12.1 RU5 |
Discussion
Symantec Endpoint Protection Manager CVE-2014-3439 Arbitrary File Write Vulnerability
Symantec Endpoint Protection Manager is prone to a vulnerability that lets attackers write or overwrite arbitrary files.
An attacker can exploit this issue to write or overwrite arbitrary files in the context of the web server, which may aid in further attacks.
Symantec Endpoint Protection Manager is prone to a vulnerability that lets attackers write or overwrite arbitrary files.
An attacker can exploit this issue to write or overwrite arbitrary files in the context of the web server, which may aid in further attacks.
Exploit / POC
Symantec Endpoint Protection Manager CVE-2014-3439 Arbitrary File Write Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Symantec Endpoint Protection Manager CVE-2014-3439 Arbitrary File Write Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.