CVE-2012-0295

The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:symantec:endpoint_protection:12.1:*:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:12.1.671:*:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:12.1.1000:*:*:*:*:*:*:*

History

21 Nov 2024, 01:34

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/53183 - () http://www.securityfocus.com/bid/53183 -
References () http://www.securityfocus.com/bid/53184 - () http://www.securityfocus.com/bid/53184 -
References () http://www.securitytracker.com/id?1027093 - () http://www.securitytracker.com/id?1027093 -
References () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120522_01 - Vendor Advisory () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120522_01 - Vendor Advisory

Information

Published : 2012-05-23 21:55

Updated : 2025-04-11 00:51


NVD link : CVE-2012-0295

Mitre link : CVE-2012-0295

CVE.ORG link : CVE-2012-0295


JSON object : View

Products Affected

symantec

  • endpoint_protection
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')