« Volver al listado

CVE-2019-9694

Estado: ModificadaAlta (7.8)—

Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-9694",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@symantec.com",
      "affectedData": [
        {
          "vendor": "Symantec",
          "product": "Symantec Endpoint Encryption",
          "versions": [
            {
              "status": "affected",
              "version": "Prior to SEE 11.2.1 MP1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-04-10T20:29:01.257",
  "references": [
    {
      "url": "https://support.symantec.com/en_US/article.SYMSA1478.html",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "secure@symantec.com"
    },
    {
      "url": "https://support.symantec.com/en_US/article.SYMSA1478.html",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user."
    },
    {
      "lang": "es",
      "value": "Symantec Endpoint Encryption anterior a versión SEE 11.2.1 MP1, puede ser susceptible a una vulnerabilidad de Escalada de Privilegios, que es un tipo de problema por del cual un atacante puede intentar comprometer la aplicación del software para conseguir un acceso elevado a los recursos que están normalmente protegidos en una aplicación o usuario."
    }
  ],
  "lastModified": "2026-06-17T02:44:11.373",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symantec:endpoint_encryption:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "979A576B-86AF-4E98-B7D0-BC26C6AF4B2F"
            },
            {
              "criteria": "cpe:2.3:a:symantec:endpoint_encryption:11.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0EB4314-B7E1-4C4E-BD76-8619B4DBAA45"
            },
            {
              "criteria": "cpe:2.3:a:symantec:endpoint_encryption:11.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EDD7ACA-241C-42A8-B7AC-B58113A3F00E"
            },
            {
              "criteria": "cpe:2.3:a:symantec:endpoint_encryption:11.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E5CDC0C-0549-4F3D-984F-D503C39D41C5"
            },
            {
              "criteria": "cpe:2.3:a:symantec:endpoint_encryption:11.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F47F13B9-755B-4088-82BF-897C4684AC77"
            },
            {
              "criteria": "cpe:2.3:a:symantec:endpoint_encryption:11.1.3:hf2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84CECDFC-9D2D-486E-8EAA-67997413E0B0"
            },
            {
              "criteria": "cpe:2.3:a:symantec:endpoint_encryption:11.1.3:hf3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6F031BD-4AD8-4410-8B4B-796A893C44E3"
            },
            {
              "criteria": "cpe:2.3:a:symantec:endpoint_encryption:11.1.3:mp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F61AFDF-E317-4B52-85F5-27B485650003"
            },
            {
              "criteria": "cpe:2.3:a:symantec:endpoint_encryption:11.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDE7435A-ED8F-438A-A2BC-E655E47F188B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@symantec.com"
}