CVE-2012-0289 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 1.5% (pctl 73)
Patch early
A public exploit exists.
Description
Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.710x allows local users to gain privileges, and modify data or cause a denial of service, via a crafted script.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 1.46% — more likely to be exploited than 73% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-05-23 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| symantec | endpoint protection |
| symantec | network access control |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Symantec End Point Protection 11.x / Symantec Network Access Control 11.x - Local Code Execution (PoC) | 2012-05-23 |
References
- http://www.securityfocus.com/bid/51795
- http://www.securitytracker.com/id?1027093
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120522_01
- http://www.securityfocus.com/bid/51795
- http://www.securitytracker.com/id?1027093
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120522_01
→ the Explorer · watch your stack · NVD