All 13 CVE vulnerabilities found in Symantec Endpoint Protection, with AI-generated Chinese analysis, references, and POCs.
This page aggregates known vulnerability data for the Symantec Endpoint Protection product, focusing on common software weakness categories identified in its codebase. It collects a comprehensive range of security flaws, including buffer overflows, injection flaws, and improper access control issues that affect the endpoint protection agent and its management console. The dataset spans from the initial release of the software through recent updates, capturing both historical and newly disclosed security advisories issued by Broadcom, the current vendor following the acquisition of Symantec’s enterprise security business. By organizing these entries systematically, the resource allows security professionals to track vendor-specific advisories and patch releases in one centralized location. Users can also gain a deeper understanding of specific weakness classes as they manifest in this particular environment, observing how abstract CVE identifiers translate into real-world configuration risks. Furthermore, the page facilitates the lookup of a product’s vulnerability history, enabling analysts to assess the long-term security posture and remediation pace of the Symantec Endpoint Protection suite. This context is essential for organizations managing legacy deployments or planning migration strategies, as it highlights persistent risk areas that may require additional compensating controls. The aggregation aims to provide clarity amidst the volume of security notifications, helping teams prioritize remediation efforts based on severity and exploitability rather than sifting through scattered press releases. Ultimately, this resource serves as a factual reference for vulnerability management, supporting informed decision-making regarding updates, version upgrades, and security hardening measures for enterprise endpoints.
Vendor: Symantec Corporation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-3599 | Symantec Endpoint Protection Elevation of Privilege CWE-367 | 6.5 | Medium | 2025-04-30 |
| CVE-2022-25631 | Symantec Endpoint Protection 安全漏洞 | 7.8 | - | 2023-01-20 |
| CVE-2022-37016 | Symantec Endpoint Protection 安全漏洞 | 8.4 | - | 2022-12-01 |
| CVE-2022-37017 | Symantec Endpoint Protection 安全漏洞 | 9.1 | - | 2022-12-01 |
| CVE-2020-5837 | Symantec Endpoint Protection 后置链接漏洞 | 7.8 | - | 2020-05-11 |
| CVE-2020-5836 | Symantec Endpoint Protection 安全漏洞 | 7.8 | - | 2020-05-11 |
| CVE-2019-18372 | Symantec Endpoint Protection Manager 安全漏洞 | 7.8 | - | 2019-11-15 |
| CVE-2019-12758 | Symantec Endpoint Protection 输入验证错误漏洞 | 7.8 | - | 2019-11-15 |
| CVE-2018-5236 | Symantec Endpoint Protection 竞争条件漏洞 | 6.3 | - | 2018-06-20 |
| CVE-2018-5237 | Symantec Endpoint Protection 权限许可和访问控制问题漏洞 | 8.8 | - | 2018-06-20 |
| CVE-2017-13680 | Symantec Endpoint Protection 安全漏洞 | 5.5 | - | 2017-11-06 |
| CVE-2017-13681 | Symantec Endpoint Protection 权限许可和访问控制问题漏洞 | 7.8 | - | 2017-11-06 |
| CVE-2017-6331 | Symantec Endpoint Protection 安全漏洞 | 7.1 | - | 2017-11-06 |
All 13 known CVE vulnerabilities affecting Symantec Endpoint Protection with full Chinese analysis, references, and POCs where available.