Vulnerability record · CVE-2012-2957 · published 23 July 2012
CVE-2012-2957: Symantec Web Gateway management console local privilege escalation via file inclusion
Symantec · Web Gateway
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 permits local users to gain privileges by modifying files, described as a file inclusion issue. Because the flaw yields full confidentiality, integrity and availability impact on the host, it matters for any deployment where untrusted local accounts or processes can reach the console's files.
Description
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw gives complete host compromise with no authentication required, though it needs local access and a patch is available.
What it is
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 permits local users to gain privileges by modifying files, described as a file inclusion issue. Because the flaw yields full confidentiality, integrity and availability impact on the host, it matters for any deployment where untrusted local accounts or processes can reach the console's files.
Impact
An attacker with local access gains elevated privileges on the appliance, giving full control over confidentiality, integrity and availability of the affected system.
Attack surface
Reached locally through the management console; the CVSS vector AV:L/AC:L/Au:N/C:C/I:C/A:C indicates no authentication is required and no user interaction beyond local access. No remote or network vector is described.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is high at roughly 0.59 (99th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Upgrade Symantec Web Gateway to 5.0.3.18 or later, which the advisory identifies as the fixed release.
- Restrict local login and shell access on the appliance to trusted administrators only.
- Audit and lock down file permissions on management console files so non-privileged users cannot modify them.
- Monitor the vendor advisory and CERT/CC note for any updated guidance or workarounds.
Detection
- Alert on unexpected changes to management console files or directories on Web Gateway hosts.
- Monitor for local privilege escalation attempts and unusual process execution by non-administrative accounts.
- Review authentication and local session logs for anomalous console access patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-2957 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-2957), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.