CVE-2018-12245: Symantec Endpoint Protection

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case is an issue that can occur when an application being installed unintentionally loads a DLL provided by a potential attacker. Note that this particular type of exploit only manifests at install time; no remediation is required for software that has already been installed. This issue only impacted the Trialware media for Symantec Endpoint Protection, which has since been updated.

Affected products

  • Symantec Endpoint Protection: from 11.0, up to and including 14.2.0.1

Published 2018-11-29. Last modified 2026-06-17.