← Back

CVE-2018-18366

nvd nist
Published: Apr 25, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Exploitability: 2.0 / Impact: 4.0
Source: NVD

Description

Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can cause the driver to return uninitialized memory.

Affected (53)

4 products
Endpoint Protection
Endpoint Protection Cloud
Endpoint Protection Cloud Agent
Norton Security
Configuration A
53 vulnerable
Vulnerable SoftwareAffected Versions
Symantec
Version 11.0
Version 11.0 mr1
Version 11.0 mr2
Version 11.0 mr3
Version 11.0 mr4-mp2
Version 11.0 mr4
Version 11.0 ru5
Version 11.0 ru6-mp1
Version 11.0 ru6-mp2
Version 11.0 ru6-mp3
Version 11.0 ru6
Version 11.0 ru6a
Version 11.0 ru7-mp1
Version 11.0 ru7-mp2
Version 11.0 ru7-mp4
Version 11.0 ru7-mp4a
Version 11.0 ru7
Version 11.0 ry7-mp3
Version 12.1
Version 12.1 ru1-mp1
Version 12.1 ru1
Version 12.1 ru2-mp1
Version 12.1 ru2
Version 12.1 ru3
Version 12.1 ru4-mp1
Version 12.1 ru4-mp1a
Version 12.1 ru4-mp1b
Version 12.1 ru4
Version 12.1 ru4a
Version 12.1 ru5
Version 12.1 ru6-mp10
Version 12.1 ru6-mp1
Version 12.1 ru6-mp2
Version 12.1 ru6-mp3
Version 12.1 ru6-mp4
Version 12.1 ru6-mp5
Version 12.1 ru6-mp6
Version 12.1 ru6-mp7
Version 12.1 ru6-mp8
Version 12.1 ru6
Version 14.0.0 mp2
Version 14.0.1
Version 14.0.1 mp1
Version 14.0.1 mp2
Version 14.2
Version 14.2 mp1
Version 14
Version 14 mp1
Version nis-22.15.2.22
Version sep-12.1.7484.7002
Before 22.16.3
Before 3.00.31.2817
Before 22.16.3

References (4)

Source: secure@symantec.com
Third Party AdvisoryVDB Entry
Source: secure@symantec.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.