Home
CRITICAL: 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H9.3 AV:N/AC:M/Au:N/C:C/I:C/A:CDefault status
unaffected
12.0 (semver)
affected
Description
A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.
Problem types
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Product status
12.0 (semver)
Credits
Exodus Intelligence
References
blog.exodusintel.com/...ffer-overflow-remote-code-execution/
blog.exodusintel.com/...ffer-overflow-remote-code-execution/