CVE-2019-12759: Symantec Endpoint Protection Manager

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Symantec Endpoint Protection Manager (SEPM) and Symantec Mail Security for MS Exchange (SMSMSE), prior to versions 14.2 RU2 and 7.5.x respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

Affected products

  • Symantec Endpoint Protection Manager: up to and including 14.2; version 14.2 only
  • Symantec Mail Security: before 7.5 (fixed in 7.5)

Published 2019-11-15. Last modified 2026-06-17.