The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

vulnerability bulletin CVE-2015-8156

Symantec Endpoint Encryption: privilege escalation via EEDService

Synthesis of the vulnerability

A local attacker can put a malicious DLL in the path of EEDService of Symantec Endpoint Encryption, in order to escalate his privileges.
Impacted products: Symantec Endpoint Encryption.
Severity of this bulletin: 2/4.
Consequences of an intrusion: administrator access/rights, privileged access/rights.
Hacker's origin: user shell.
Creation date: 09/05/2016.
Références of this threat: BID-90050, CVE-2015-8156, SYM16-006, VIGILANCE-VUL-19563.

Description of the vulnerability

The Symantec Endpoint Encryption product installs the EEDService service.

However, the access path to a DLL is not quoted.

A local attacker can therefore put a malicious DLL in the path of EEDService of Symantec Endpoint Encryption, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

Computer vulnerabilities tracking service

Vigil@nce provides an application vulnerability watch. The Vigil@nce computer vulnerability tracking service alerts your teams of vulnerabilities or threats impacting your information system. Each administrator can customize the list of products for which he wants to receive vulnerability alerts. The Vigil@nce vulnerability database contains several thousand vulnerabilities.