Vulnerability record · CVE-2015-1487 · published 1 August 2015
CVE-2015-1487: Symantec Endpoint Protection Manager arbitrary file write via crafted filename
Symantec · Endpoint Protection Manager
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 fails to properly validate filenames, allowing remote authenticated users to write to arbitrary files. Because the console runs with elevated privileges, this file write can be leveraged to obtain administrator privileges on the SEPM server.
Description
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator privileges, via a crafted filename.
AV:N/AC:L/Au:S/C:N/I:P/A:P
Automated analysis
high priorityA public exploit exists and EPSS is very high, and successful exploitation yields administrator control of the endpoint management server, though authentication is required.
What it is
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 fails to properly validate filenames, allowing remote authenticated users to write to arbitrary files. Because the console runs with elevated privileges, this file write can be leveraged to obtain administrator privileges on the SEPM server.
Impact
An attacker with a valid low-privileged account can write arbitrary files on the SEPM host and escalate to administrator privileges, gaining control of the endpoint management infrastructure.
Attack surface
Reachable over the network through the SEPM management console; the attacker must be authenticated with a valid account, and no user interaction is required from a victim.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but a public Exploit-DB entry exists and EPSS is high (0.51977, 98.9th percentile), indicating meaningful exploitation likelihood.
What to do
- Upgrade SEPM 12.1 to 12.1-RU6-MP1 or later as specified in the vendor advisory.
- Restrict network access to the SEPM management console to trusted administrative networks.
- Enforce least privilege and review SEPM accounts, removing or disabling unused low-privileged accounts.
- Monitor and alert on unexpected file creation or modification in SEPM installation and system directories.
Detection
- Audit SEPM console logs for file upload or filename parameters containing path traversal sequences or absolute paths.
- Monitor file system changes in SEPM directories for files created by the SEPM service account outside expected paths.
- Alert on new administrator account creation or privilege changes on the SEPM host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-1487 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1487), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.