CVE-2018-12245: Symantec Endpoint Protection
High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case is an issue that can occur when an application being installed unintentionally loads a DLL provided by a potential attacker. Note that this particular type of exploit only manifests at install time; no remediation is required for software that has already been installed. This issue only impacted the Trialware media for Symantec Endpoint Protection, which has since been updated.
Affected products
- Symantec Endpoint Protection: from 11.0, up to and including 14.2.0.1
Published 2018-11-29. Last modified 2026-06-17.