CVE-2012-4350
Published Dec 18, 2012
Last updated 12 years ago
Overview
- Description
- Multiple unquoted Windows search path vulnerabilities in the (1) Manager and (2) Agent components in Symantec Enterprise Security Manager (ESM) before 11.0 allow local users to gain privileges via unspecified vectors.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Evaluator
- Comment
- Per http://cwe.mitre.org/data/definitions/426.html 'CWE-426: Untrusted Search Path'
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:symantec:enterprise_security_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "139DC390-948B-401F-B958-455B8B31E5F9", "versionEndIncluding": "10.0" }, { "criteria": "cpe:2.3:a:symantec:enterprise_security_manager:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7D3219F-1AC4-4ED6-ACE0-CB33A104F484" }, { "criteria": "cpe:2.3:a:symantec:enterprise_security_manager:6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5296D33B-5F71-4DE3-B5CD-9328F091CEA9" }, { "criteria": "cpe:2.3:a:symantec:enterprise_security_manager:6.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B1CD675-463B-42DA-B0D9-0C09C33A7BEA" }, { "criteria": "cpe:2.3:a:symantec:enterprise_security_manager:6.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8D5C43D9-37D5-4981-87EF-BE7FAB2D1531" }, { "criteria": "cpe:2.3:a:symantec:enterprise_security_manager:6.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9BC1C6DE-0C86-4A16-A432-3AB93AC1A754" }, { "criteria": "cpe:2.3:a:symantec:enterprise_security_manager:6.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7082C313-6747-4A49-B137-0CE2CB3ADB4F" }, { "criteria": "cpe:2.3:a:symantec:enterprise_security_manager:9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA255472-FE79-4395-A2CD-F527168CBDE0" }, { "criteria": "cpe:2.3:a:symantec:enterprise_security_manager:9.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "638FEDA4-7C80-46A9-83C0-E03D61AF6B1D" } ], "operator": "OR" } ] } ]