CVE-2018-18366: Symantec Endpoint Protection
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can cause the driver to return uninitialized memory.
Affected products
- Symantec Endpoint Protection: version 11.0 only; version 12.1 only; version 14 only; version 14.0.0 only; version 14.0.1 only; version 14.2 only; …
- Symantec Endpoint Protection Cloud: before 22.16.3 (fixed in 22.16.3)
- Symantec Endpoint Protection Cloud Agent: before 3.00.31.2817 (fixed in 3.00.31.2817)
- Symantec Norton Security: before 22.16.3 (fixed in 22.16.3)
Published 2019-04-25. Last modified 2026-06-17.