Lucene search

K
cveSymantecCVE-2015-8156
HistoryMay 14, 2016 - 1:59 a.m.

CVE-2015-8156

2016-05-1401:59:00
symantec
web.nvd.nist.gov
31
cve-2015-8156
eedservice
symantec endpoint encryption
windows vulnerability
local privilege escalation
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

9.5%

Unquoted Windows search path vulnerability in EEDService in Symantec Endpoint Encryption (SEE) 11.x before 11.1.1 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.

Affected configurations

Nvd
Node
symantecendpoint_encryptionMatch11.0
OR
symantecendpoint_encryptionMatch11.0.0
OR
symantecendpoint_encryptionMatch11.0.1
VendorProductVersionCPE
symantecendpoint_encryption11.0cpe:2.3:a:symantec:endpoint_encryption:11.0:*:*:*:*:*:*:*
symantecendpoint_encryption11.0.0cpe:2.3:a:symantec:endpoint_encryption:11.0.0:*:*:*:*:*:*:*
symantecendpoint_encryption11.0.1cpe:2.3:a:symantec:endpoint_encryption:11.0.1:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

9.5%