CVE-2020-5837

Description

Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.77

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Symantec Endpoint Protection (x64) 14.2Windows
Multiple Vulnerabilities are affected in Symantec Endpoint Protection 14.2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234