Symantec Endpoint Protection Client 12.1.x < 12.1 RU6 MP7 / 14.0.x < 14.0 MP1 Command Injection (SYM17-002)

This script is Copyright (C) 2017 Tenable Network Security, Inc.


Synopsis :

The Symantec Endpoint Protection Client installed on the remote host
is affected by a command injection vulnerability.

Description :

The version of Symantec Endpoint Protection (SEP) Client installed on
the remote host is 12.1.x prior to 12.1 RU6 MP7 or 14.0.x prior to
14.0 MP1. It is, therefore, affected by a command injection
vulnerability when handling quarantine logs due to file metadata being
improperly interpreted and evaluated as a formula when exporting logs
into CSV format for review. An unauthenticated, remote attacker can
exploit this, by convincing a user into exporting and opening
specially crafted quarantine logs in CVS format, to inject malicious
formulas into the exported logs, resulting in the execution of
arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied
only on the application's self-reported version number.

See also :

http://www.nessus.org/u?0a546db1

Solution :

Upgrade to Symantec Endpoint Protection Client version 12.1 RU6 MP7 /
14.0 MP1 or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.6
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 100593 ()

Bugtraq ID: 96298

CVE ID: CVE-2016-9094

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now