CVE-2020-5836

Description

Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec Endpoint Protections Tamper Protection feature is disabled.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.072

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Symantec Endpoint Protection (x64) 14.2Windows
Multiple Vulnerabilities are affected in Symantec Endpoint Protection 14.2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234