CVE-2016-9093 CVE-2016-9094

Symantec Endpoint Protection: two vulnerabilities

Synthesis of the vulnerability

An attacker can use several vulnerabilities of Symantec Endpoint Protection.
Impacted products: SEP.
Severity of this bulletin: 3/4.
Consequences of an intrusion: administrator access/rights, privileged access/rights, user access/rights, denial of service on client.
Hacker's origin: document.
Number of vulnerabilities in this bulletin: 2.
Creation date: 07/03/2017.
Références of this threat: CVE-2016-9093, CVE-2016-9094, SYM17-002, VIGILANCE-VUL-22029.

Description of the vulnerability

Several vulnerabilities were announced in Symantec Endpoint Protection.

An attacker can generate a memory corruption via the SymEvent driver, in order to trigger a denial of service, and possibly to run code with kernel privileges. [severity:3/4; CVE-2016-9093]

An attacker can make the product record data about a verified file in such a way that executable formula will be run after a log export to a spreadsheet. [severity:2/4; CVE-2016-9094]
