CVE-2022-37017 Information

Description

Symantec Endpoint Protection (Windows) agent prior to 14.3 RU6/14.3 RU5 Patch 1 may be susceptible to a Security Control Bypass vulnerability which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection if it has been enabled.

Reference

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/21014

Share on: