CVE-2012-4350: Symantec Enterprise Security Manager

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Multiple unquoted Windows search path vulnerabilities in the (1) Manager and (2) Agent components in Symantec Enterprise Security Manager (ESM) before 11.0 allow local users to gain privileges via unspecified vectors.

Affected products

  • Symantec Enterprise Security Manager: up to and including 10.0; version 6.0 only; version 6.5 only; version 6.5.0 only; version 6.5.1 only; version 6.5.2 only; …

Published 2012-12-18. Last modified 2026-06-16.