Lucene search

K
nvd[email protected]NVD:CVE-2014-3434
HistoryAug 06, 2014 - 7:55 p.m.

CVE-2014-3434

2014-08-0619:55:03
CWE-119
web.nvd.nist.gov
5

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

42.7%

Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition before SEP 12.1, allows local users to execute arbitrary code via a long argument to a 0x00222084 IOCTL call.

Affected configurations

Nvd
Node
symantecendpoint_protectionMatch11.0
OR
symantecendpoint_protectionMatch12.0-small_business
OR
symantecendpoint_protectionMatch12.1
VendorProductVersionCPE
symantecendpoint_protection11.0cpe:2.3:a:symantec:endpoint_protection:11.0:*:*:*:*:*:*:*
symantecendpoint_protection12.0cpe:2.3:a:symantec:endpoint_protection:12.0:-:small_business:*:*:*:*:*
symantecendpoint_protection12.1cpe:2.3:a:symantec:endpoint_protection:12.1:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

42.7%