Arbitrary Code Execution Vulnerability in Symantec Endpoint Protection

Arbitrary Code Execution Vulnerability in Symantec Endpoint Protection

CVE-2015-8154 · HIGH Severity

AV:N/AC:M/AU:N/C:C/I:C/A:C

The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4 allows remote attackers to execute arbitrary code via a crafted HTML document, related to "RWX Permissions."

Learn more about our Web Application Penetration Testing UK.