← Vulnerability feed

Vulnerability record · CVE-2015-1487 · published 1 August 2015

CVE-2015-1487: Symantec Endpoint Protection Manager arbitrary file write via crafted filename

Symantec · Endpoint Protection Manager

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 fails to properly validate filenames, allowing remote authenticated users to write to arbitrary files. Because the console runs with elevated privileges, this file write can be leveraged to obtain administrator privileges on the SEPM server.

5.5 CVSS 2.0 Medium EPSS 52% · top 1.1% CWE-20 · Improper input validation
5.5CVSS 2.0 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator privileges, via a crafted filename.

AV:N/AC:L/Au:S/C:N/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityA public exploit exists and EPSS is very high, and successful exploitation yields administrator control of the endpoint management server, though authentication is required.

What it is

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 fails to properly validate filenames, allowing remote authenticated users to write to arbitrary files. Because the console runs with elevated privileges, this file write can be leveraged to obtain administrator privileges on the SEPM server.

Impact

An attacker with a valid low-privileged account can write arbitrary files on the SEPM host and escalate to administrator privileges, gaining control of the endpoint management infrastructure.

Attack surface

Reachable over the network through the SEPM management console; the attacker must be authenticated with a valid account, and no user interaction is required from a victim.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but a public Exploit-DB entry exists and EPSS is high (0.51977, 98.9th percentile), indicating meaningful exploitation likelihood.

What to do

  • Upgrade SEPM 12.1 to 12.1-RU6-MP1 or later as specified in the vendor advisory.
  • Restrict network access to the SEPM management console to trusted administrative networks.
  • Enforce least privilege and review SEPM accounts, removing or disabling unused low-privileged accounts.
  • Monitor and alert on unexpected file creation or modification in SEPM installation and system directories.

Detection

  • Audit SEPM console logs for file upload or filename parameters containing path traversal sequences or absolute paths.
  • Monitor file system changes in SEPM directories for files created by the SEPM service account outside expected paths.
  • Alert on new administrator account creation or privilege changes on the SEPM host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-1487 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-3650Symantec endpoint protection manager information exposure vulnerabilitySymantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.EPSS 1.5%8.8CVE-2016-3648Symantec endpoint protection manager information exposure vulnerabilitySymantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechan…EPSS 2.3%8.8CVE-2015-8154Symantec endpoint protection manager permissions and access controls vulnerabilityThe SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4…EPSS 5.0%8.8CVE-2015-8153Symantec endpoint protection manager sql injection vulnerabilitySQL injection vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to execute arbitrary…EPSS 3.1%8.5CVE-2015-6555Symantec endpoint protection manager code injection vulnerabilitySymantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary Java code by connecting to the cons…EPSS 2.8%8.5CVE-2015-1492Symantec endpoint protection manager improper input validation vulnerabilityUntrusted search path vulnerability in the client in Symantec Endpoint Protection 12.1 before 12.1-RU6-MP1 allows local users to gain privileges via …EPSS 1.7%8.5CVE-2015-1489Symantec endpoint protection manager permissions and access controls vulnerabilityThe management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges v…EPSS 25%8.0CVE-2016-3653Symantec endpoint protection manager cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 a…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2015-1487), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.