Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.71% | — | Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Norton 360Symantec Norton Antivirus+5 | 9/1/2020 | 17/6/2026 | A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due to a DLL-preloading without path… | |
| Modificada | Alta (7.8) | 0.40% | — | Symantec Endpoint Protection | 15/11/2019 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. | |
| Modificada | Alta (7.8) | 0.48% | — | Symantec Endpoint Protection ManagerSymantec Mail Security | 15/11/2019 | 17/6/2026 | Symantec Endpoint Protection Manager (SEPM) and Symantec Mail Security for MS Exchange (SMSMSE), prior to versions 14.2 RU2 and 7.5.x respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain… | |
| Modificada | Media (6.7) | 0.66% | — | Symantec Endpoint Protection | 15/11/2019 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which may allow an individual to execute code without a resident proper digital signature. | |
| Modificada | Alta (7.8) | 0.40% | — | Symantec Endpoint Protection | 15/11/2019 | 17/6/2026 | Symantec Endpoint Protection (SEP), prior to 14.2 RU2 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to 12.1 RU6 MP10d (12.1.7510.7002), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the… | |
| Modificada | Baja (2.3) | 0.30% | — | Symantec Endpoint Protection | 15/11/2019 | 17/6/2026 | Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability whereby the secondary layer of password protection could by bypassed for individuals with local administrator rights. | |
| Modificada | Alta (7.8) | 0.58% | 💥 PoC | Symantec Endpoint Protection Manager | 15/11/2019 | 17/6/2026 | Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. | |
| Modificada | Alta (7.5) | 4.1% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 23/9/2019 | 17/6/2026 | A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'. | |
| Modificada | Alta (7.1) | 0.95% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 14/8/2019 | 17/6/2026 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete… | |
| Modificada | Alta (7.8) | 1.3% | 💥 PoC | Symantec Endpoint Protection | 31/7/2019 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.2 RU1 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition, prior to 12.1 RU6 MP10c (12.1.7491.7002), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application… | |
| Modificada | Alta (7.8) | 1.7% | — | Symantec Endpoint Protection Manager | 25/4/2019 | 17/6/2026 | Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. | |
| Modificada | Media (6.5) | 0.39% | — | Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Endpoint Protection Cloud AgentSymantec Norton Security | 25/4/2019 | 17/6/2026 | Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a… | |
| Modificada | Media (6.3) | 1.1% | — | Symantec Endpoint Protection | 25/4/2019 | 17/6/2026 | SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files. | |
| Modificada | Alta (7.8) | 2.4% | — | Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Endpoint Protection Cloud AgentSymantec Norton Security | 25/4/2019 | 17/6/2026 | Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker… | |
| Modificada | Alta (7.8) | 1.1% | — | Symantec Endpoint Protection | 29/11/2018 | 17/6/2026 | Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case is an issue that can occur when an application being installed unintentionally loads a DLL provided by a potential attacker. Note that this particular type of exploit only manifests at install time;… | |
| Modificada | Media (6.8) | 0.52% | — | Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Norton Antivirus | 29/11/2018 | 17/6/2026 | Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be susceptible to an AV bypass issue, which is a… | |
| Modificada | Alta (7.8) | 0.40% | — | Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Norton Antivirus | 29/11/2018 | 17/6/2026 | Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be susceptible to an AV bypass issue, which is a… | |
| Modificada | Alta (8.8) | 1.9% | — | Symantec Endpoint Protection | 20/6/2018 | 17/6/2026 | Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels. | |
| Modificada | Media (5.3) | 1.1% | — | Symantec Endpoint Protection | 20/6/2018 | 17/6/2026 | Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard). This type of issue occurs in software where the output is dependent on the sequence or timing of other uncontrollable events. | |
| Modificada | Alta (7.8) | 1.3% | — | Symantec Endpoint Protection | 16/4/2018 | 17/6/2026 | Symantec Endpoint Protection clients place detected malware in quarantine as part of the intended product functionality. The quarantine logs can be exported for review by the user in a variety of formats including .CSV files. Prior to 14.0 MP1 and 12.1 RU6 MP7, the potential exists for file metadata to be interpreted… | |
| Modificada | Alta (7) | 0.38% | — | Symantec Endpoint Protection | 16/4/2018 | 17/6/2026 | A version of the SymEvent Driver that shipped with Symantec Endpoint Protection 12.1 RU6 MP6 and earlier fails to properly sanitize logged-in user input. SEP 14.0 and later are not impacted by this issue. A non-admin user would need to be able to save an executable file to disk and then be able to successfully run… | |
| Modificada | Alta (7.8) | 1.7% | 💥 Exploit | Sophos Endpoint Protection | 5/4/2018 | 17/6/2026 | Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches. | |
| Modificada | Media (5.5) | 1.2% | 💥 Exploit | Sophos Endpoint Protection | 5/4/2018 | 17/6/2026 | Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key. | |
| Modificada | Alta (8.8) | 63% | 💥 Exploit | Microsoft Exchange ServerMicrosoft Security EssentialsMicrosoft Forefront Endpoint Protection 2010Microsoft Intune Endpoint Protection+2 | 4/4/2018 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection,… | |
| Modificada | Alta (7.1) | 1.7% | 💥 Exploit | Symantec Endpoint Protection | 6/11/2017 | 17/6/2026 | Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients. |