Is Symantec Endpoint Protection Manager affected by CVE-2024-11235?
search cancel

Is Symantec Endpoint Protection Manager affected by CVE-2024-11235?

book

Article ID: 395236

calendar_today

Updated On: 04-24-2025

Products

Endpoint Protection

Issue/Introduction

You are inquiring to see if the Symantec Endpoint Protection Manager (SEPM) is affected by the PHP vulnerability reported in CVE-2024-11235

Environment

Symantec Endpoint Protection Manager

Resolution

SEPM is NOT vulnerable to this CVE.

The assessment is based on the fact that an attacker would need to be able to manipulate a component that can trigger an exception that leads to the use-after-free and ultimately result in undefined behavior. Since none of the PHP components inside SEPM is controlled by an external entity, SEPM is not vulnerable to this CVE.