![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5837
https://notcve.org/view.php?id=CVE-2020-5837
11 May 2020 — Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege. Symantec Endpoint Protection, versiones anteriores a 14.3, puede no respetar los permisos de archivo cuando se escriben en archivos de registro que son reemplazados por enlaces simbólicos, lo que puede conllevar a una potencial elevación de privilegios. • https://github.com/RedyOpsResearchLabs/SEP-14.2-Arbitrary-Write • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5836
https://notcve.org/view.php?id=CVE-2020-5836
11 May 2020 — Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec Endpoint Protection's Tamper Protection feature is disabled. Symantec Endpoint Protection, versiones anteriores a 14.3, puede potencialmente restablecer las ACL en un archivo como un usuario limitado, mientras la funcionalidad Tamper Protection de Symantec Endpoint Protection es desactivada. • https://support.broadcom.com/security-advisory/security-advisory-detail.html?notificationId=SYMSA1762 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-9363
https://notcve.org/view.php?id=CVE-2020-9363
24 Feb 2020 — The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction. El motor de análisis Sophos AV versiones anteriores a 14-01-2020 permite una omisión de la detección de virus por medio de un archivo ZIP diseñado. Es... • https://blog.zoller.lu/p/release-mode-coordinated-disclosure-ref.html • CWE-436: Interpretation Conflict •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5821
https://notcve.org/view.php?id=CVE-2020-5821
11 Feb 2020 — Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a DLL injection vulnerability, which is a type of issue whereby an individual attempts to execute their own code in place of legitimate code as a means to perform an exploit. Symantec Endpoint Protection (SEP) y Symantec Endpoint Protection Small Business Edition (SEP SBE), versiones anteriores a 14.2 RU2 MP1 y versiones a... • https://support.symantec.com/us/en/article.SYMSA1505.html • CWE-427: Uncontrolled Search Path Element •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5826 – Symantec Endpoint Protection AvHostPlugin Out-of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-5826
11 Feb 2020 — Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program. Symantec Endpoint Protection (SEP) y Symantec Endpoint Protection Small Business Edition (SEP SBE), versiones anteriores a 14.2 RU2 MP1 ... • https://support.symantec.com/us/en/article.SYMSA1505.html • CWE-125: Out-of-bounds Read •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5823 – Symantec Endpoint Protection ccJobMgr Missing Authentication Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2020-5823
11 Feb 2020 — Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. Symantec Endpoint Protection (SEP) y Symantec Endpoint Protection Small Business Edition (SEP SB... • https://support.symantec.com/us/en/article.SYMSA1505.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5822 – Symantec Endpoint Protection ccSvc Missing Authentication Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2020-5822
11 Feb 2020 — Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. Symantec Endpoint Protection (SEP) y Symantec Endpoint Protection Small Business Edition (SEP SB... • https://support.symantec.com/us/en/article.SYMSA1505.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5824 – Symantec Endpoint Protection AvHostPlugin Missing Authentication Denial-of-Service Vulnerability
https://notcve.org/view.php?id=CVE-2020-5824
11 Feb 2020 — Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a denial of service vulnerability, which is a type of issue whereby a threat actor attempts to tie up the resources of a resident application, thereby making certain functions unavailable. Symantec Endpoint Protection (SEP) y Symantec Endpoint Protection Small Business Edition (SEP SBE), versiones anteriores a 14.2 RU2 MP1... • https://support.symantec.com/us/en/article.SYMSA1505.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5820 – Symantec Endpoint Protection AvHostPlugin Out-Of-Bounds Write Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2020-5820
11 Feb 2020 — Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. Symantec Endpoint Protection (SEP) y Symantec Endpoint Protection Small Business Edition (SEP SB... • https://support.symantec.com/us/en/article.SYMSA1505.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5825 – Symantec Endpoint Protection AvHostPlugin Missing Authentication Arbitrary File Move Vulnerability
https://notcve.org/view.php?id=CVE-2020-5825
11 Feb 2020 — Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an arbitrary file write vulnerability, which is a type of issue whereby an attacker is able to overwrite existing files on the resident system without proper privileges. Symantec Endpoint Protection (SEP) y Symantec Endpoint Protection Small Business Edition (SEP SBE), versiones anteriores a 14.2 RU2 MP1 y versiones anteri... • https://support.symantec.com/us/en/article.SYMSA1505.html •