// For flags

CVE-2018-18369

 

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.

Norton Security (cliente de Windows) anterior a la versión 22.16.3 y SEP SBE (cliente de Windows) anterior a las versiones Cloud Agent 3.00.31.2817, NIS-22.15.2.22 y SEP-12.1.7484.7002, puede ser susceptible a una vulnerabilidad de precarga de DLL, que es un tipo de problema que puede presentarse cuando una aplicación busca llamar a una DLL para su ejecución y un atacante suministra una DLL maliciosa para usar en su lugar.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-10-15 CVE Reserved
  • 2019-04-25 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-09-15 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-426: Untrusted Search Path
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
nis-22.15.2.22
Search vendor "Symantec" for product "Endpoint Protection" and version "nis-22.15.2.22"
small_business
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection
Search vendor "Symantec" for product "Endpoint Protection"
sep-12.1.7484.7002
Search vendor "Symantec" for product "Endpoint Protection" and version "sep-12.1.7484.7002"
small_business
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection Cloud
Search vendor "Symantec" for product "Endpoint Protection Cloud"
< 22.16.3
Search vendor "Symantec" for product "Endpoint Protection Cloud" and version " < 22.16.3"
-
Affected
Symantec
Search vendor "Symantec"
Endpoint Protection Cloud Agent
Search vendor "Symantec" for product "Endpoint Protection Cloud Agent"
< 3.00.31.2817
Search vendor "Symantec" for product "Endpoint Protection Cloud Agent" and version " < 3.00.31.2817"
small_business
Affected
Symantec
Search vendor "Symantec"
Norton Security
Search vendor "Symantec" for product "Norton Security"
< 22.16.3
Search vendor "Symantec" for product "Norton Security" and version " < 22.16.3"
windows
Affected