CVE-2017-13681: Symantec Endpoint Protection

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Symantec Endpoint Protection prior to SEP 12.1 RU6 MP9 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels. In the circumstances of this issue, the capability of exploit is limited by the need to perform multiple file and directory writes to the local filesystem and as such, is not feasible in a standard drive-by type attack.

Affected products

  • Symantec Endpoint Protection: before 12.1 (fixed in 12.1)

Published 2017-11-06. Last modified 2026-06-17.