CVE-2014-3434
Last modified
CVE-2014-3434 is a vulnerability of currently unknown severity. Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition before SEP 12.1, allows local users to execute arbitrary code via a long argument to a 0x00222084 IOCTL call.. EPSS estimates a 1.63% chance of exploitation in the next 30 days.
Description
Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition before SEP 12.1, allows local users to execute arbitrary code via a long argument to a 0x00222084 IOCTL call.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Endpoint Protection | 11.0 |
| Symantec | Endpoint Protection | 12.0 |
| Symantec | Endpoint Protection | 12.1 |
References
- http://www.kb.cert.org/vuls/id/252068US Government Resource
- http://www.kb.cert.org/vuls/id/252068US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3434?
How severe is CVE-2014-3434?
How do I fix CVE-2014-3434?
Are you affected by CVE-2014-3434?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
