Vulnerability Name:

CVE-2016-9094

Assigned:2016-10-28
Published:2017-03-06
Updated:2018-04-17
Summary:Symantec Endpoint Protection clients place detected malware in quarantine as part of the intended product functionality. The quarantine logs can be exported for review by the user in a variety of formats including .CSV files. Prior to 14.0 MP1 and 12.1 RU6 MP7, the potential exists for file metadata to be interpreted and evaluated as a formula. Successful exploitation of an attack of this type requires considerable direct user-interaction from the user exporting and then opening the log files on the intended target client.
CVSS v3 Severity:2.5 Low (CCN CVSS v3 Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N)
2.2 Low (CCN Temporal CVSS v3 Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:1.0 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
References:Source: BID
Type: UNKNOWN
96298

Source: SECTRACK
Type: UNKNOWN
1037961

Source: XF
Type: UNKNOWN
symantec-cve20169094-sec-bypass(122786)

Source: CONFIRM
Type: UNKNOWN
https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20170306_00

BACK