A privilege escalation vulnerability exists in Symantec Endpoint Encryption versions prior to 11.3.0. This vulnerability allows a user to gain elevated access to resources that are normally protected at lower access levels, potentially bypassing security controls enforced by the software.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real Windows local privilege escalation proof-of-concept targeting Symantec Encryption Desktop's PGPwded.sys raw disk access path, explicitly referencing CVE-2019-9702 and tested against Symantec Encryption Desktop Pro 10.4.2 MP3. The repo contains 11 files: a Makefile-based build chain, four main C source components for exploit/precheck launchers and injected workers, one C payload source, a Python helper that converts built binaries into embedded byte arrays, and a CMD diagnostic wrapper. Structure and flow: `src/spooler_payload.c` builds a replacement service binary payload. The Makefile converts that EXE into `spooler_payload_bytes.h`, which is embedded into `src/portable_stage_worker.c`. That worker DLL is then built and converted into `portable_worker_bytes.h`, which is embedded into `src/sym_portable_launcher.c`, producing a single portable exploit EXE. A parallel path builds `precheck_worker.c` into an embedded DLL used by `sym_portable_precheck.c` for read-only viability testing. Main exploit capability: the launcher drops an embedded DLL to `%TEMP%`, locates a trusted Symantec PGP executable (`PGPdesk.exe`), starts or reuses it, and injects the worker via `CreateRemoteThread`/`LoadLibraryW`. Running inside the trusted PGP process context, the worker opens `\\.\PGPwdef`, maps `C:\Windows\System32\spoolsv.exe` to its NTFS retrieval pointers, computes the backing disk sector, enumerates `\Device\00000000`-style PDO names, and uses raw read IOCTL `0x8002206c` to find which PDO maps to the target sector. It then backs up the original spooler binary to `C:\Users\Public\spoolsv.exe.orig.portable` and uses raw write IOCTL `0x80022070` to overwrite the sectors backing `spoolsv.exe` with the embedded payload. After reboot, the Windows Spooler service starts the overwritten binary as LocalSystem. Payload behavior: the replacement spooler payload registers as service `Spooler`, logs execution, enables token-related privileges, finds `winlogon.exe` in the active console session, duplicates its token, and launches `C:\Windows\System32\cmd.exe /k whoami & title SYSTEM_CMD_FROM_PORTABLE_REBOOT_LPE` on `winsta0\default`, yielding an interactive visible SYSTEM shell. It also writes a proof file to `C:\Users\Public\portable_reboot_payload_proof.txt`. Precheck capability: the precheck follows the same trusted-process injection model but only performs diagnostics. It verifies writable public path access, confirms direct System32 writes are denied to the low-privileged user, maps `spoolsv.exe`, checks extent count and size, opens `\\.\PGPwdef`, enumerates readable PDOs with raw read IOCTL `0x8002206c`, and determines whether the target C: sector is readable through the Symantec device path. It reports whether current reboot exploit conditions are present. Overall, this is not a scanner-only repository: it contains a functioning local exploit chain with a hardcoded but effective payload. It is best classified as OPERATIONAL rather than WEAPONIZED because the payload and target are fixed (`spoolsv.exe`, visible SYSTEM cmd) and not generalized into a reusable framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.