Description
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Marc Bevand · perlremotewindows
https://www.exploit-db.com/exploits/1703
Scores
EPSS
0.3269
EPSS Percentile
96.9%
Details
Status
published
Products (1)
symantec/antivirus_scan_engine
5.0.0.24
Published
Apr 25, 2006
Tracked Since
Feb 18, 2026