VendorsCiscoadvanced_malware_protection_for_endpointsall versions
Vulnerabilities

Cisco Advanced Malware Protection

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2021-1280
Cisco Advanced Malware Protection for Endpoints and Immunet for Windows DLL Hijacking Vulnerability
Published 2021-01-20 · Modified
7.8EPSS 0.004
CVE-2021-1386
Cisco Advanced Malware Protection for Endpoints Windows Connector, ClamAV for Windows, and Immunet DLL Hijacking Vulnerability
Published 2021-04-08 · Modified
7.8EPSS 0.003
CVE-2017-12312
An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installer in the current working directory where a crafted DLL has been placed by an attacker. The vulnerability is due to incomplete input validation of path and file names of a DLL file before it is loaded. An attacker could exploit this vulnerability by creating a malicious DLL file and installing it in a specific system directory. A successful exploit could allow the attacker to execute commands on the underlying Microsoft Windows host with privileges equivalent to the SYSTEM account. An attacker would need valid user credentials to exploit this vulnerability. Cisco Bug IDs: CSCvf23928.
Published 2017-11-16 · Modified
7.2EPSS 0.005
CVE-2019-1932
Cisco Advanced Malware Protection for Endpoints Windows Command Injection Vulnerability
Published 2019-07-06 · Modified
7.2EPSS 0.003
CVE-2018-0397
A vulnerability in Cisco AMP for Endpoints Mac Connector Software installed on Apple macOS 10.12 could allow an unauthenticated, remote attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. The vulnerability exists if the affected software is running in Block network conviction mode. Exploitation could occur if the system that is running the affected software starts a server process and an address in the IP blacklist cache of the affected software attempts to connect to the affected system. A successful exploit could allow the attacker to cause a kernel panic on the system that is running the affected software, resulting in a DoS condition. Cisco Bug IDs: CSCvk08192.
Published 2018-08-01 · Modified
7.1EPSS 0.015
CVE-2018-15452
Cisco Advanced Malware Protection for Endpoints on Windows DLL Preloading Vulnerability
Published 2018-11-13 · Modified
6.7EPSS 0.003
CVE-2020-3350
Cisco AMP for Endpoints and ClamAV Privilege Escalation Vulnerability
Published 2020-06-18 · Modified
6.3EPSS 0.003
CVE-2020-3314
Cisco AMP for Endpoints Mac Connector Software File Scan Denial of Service Vulnerability
Published 2020-05-22 · Modified
6.1EPSS 0.006
CVE-2018-0237
A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerability occurs because the software relies on only the file extension for detecting DMG files. An attacker could exploit this vulnerability by sending a DMG file with a nonstandard extension to a device that is running an affected AMP for Endpoints macOS Connector. An exploit could allow the attacker to bypass configured malware detection. Cisco Bug IDs: CSCve34034.
Published 2018-04-19 · Modified
5.8EPSS 0.012
CVE-2018-15437
Cisco Immunet and Cisco AMP for Endpoints System Scan Denial of Service Vulnerability
Published 2018-11-08 · Modified
5.51 PoCEPSS 0.010
CVE-2020-3343
Cisco AMP for Endpoints Linux Connector and AMP for Endpoints Mac Connector Software Memory Buffer Vulnerability
Published 2020-05-22 · Modified
5.5EPSS 0.003
CVE-2020-3344
Cisco AMP for Endpoints Linux Connector and AMP for Endpoints Mac Connector Software Memory Buffer Vulnerability
Published 2020-05-22 · Modified
5.5EPSS 0.003