CVE-2015-4523
CRITICALSymantec Malware Analysis Appliance < 4.2 - Access Control
Title source: ruleDescription
Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanism and consequently write to arbitrary files, cause a denial of service (host reboot or reset to factory defaults), or execute arbitrary code via vectors related to saving files during analysis.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows_x86-64
https://www.exploit-db.com/exploits/34334
Scores
CVSS v3
9.3
EPSS
0.0549
EPSS Percentile
90.2%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-264
Status
published
Products (2)
symantec/malware_analysis_appliance
< 4.2
symantec/malware_analyzer_g2
< 3.5
Published
Sep 11, 2017
Tracked Since
Feb 18, 2026