QID 379348

Date Published: 2024-02-06

QID 379348: Symantec Data Loss Prevention Buffer Overflow Vulnerability

A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.

Affected Versions:
Symantec Data Loss Prevention 14.0.2 and before
QID Detection Logic (Authenticated)
This checks for version of SymantecDLPManager.exe file.

A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    The affected product is end-of-life and no patches are available.
    Vendor References

    CVEs related to QID 379348

    Software Advisories
    Advisory ID Software Component Link