Vulnerability Description
SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Endpoint Protection | 11.0 |
Related Weaknesses (CWE)
References
- https://support.symantec.com/en_US/article.SYMSA1479.htmlVendor Advisory
- https://www.securityfocus.com/bid/107999Third Party AdvisoryVDB Entry
- https://support.symantec.com/en_US/article.SYMSA1479.htmlVendor Advisory
- https://www.securityfocus.com/bid/107999Third Party AdvisoryVDB Entry
FAQ
What is CVE-2018-12244?
CVE-2018-12244 is a vulnerability with a CVSS score of 6.3 (MEDIUM). SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby a...
How severe is CVE-2018-12244?
CVE-2018-12244 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12244?
Check the references section above for vendor advisories and patch information. Affected products include: Symantec Endpoint Protection.