CVE-2016-2207

HIGH

Symantec AntiVirus Decomposer Engine - Remote Code Execution via Crafted RAR File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-2207. PoCs published by Google Security Research.

AI-analyzed exploit summary The writeup describes a vulnerability in Symantec Antivirus products where the decomposer component, based on an outdated version of the unrar library, contains multiple memory corruption bugs. These can lead to remote code execution as SYSTEM on Windows or root on Linux/Mac.

Description

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation) via a crafted RAR file that is mishandled during decompression.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/40031

The writeup describes a vulnerability in Symantec Antivirus products where the decomposer component, based on an outdated version of the unrar library, contains multiple memory corruption bugs. These can lead to remote code execution as SYSTEM on Windows or root on Linux/Mac.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Symantec Antivirus (Norton Antivirus, Symantec Endpoint Protection, Symantec Scan Engine)
No auth needed
Prerequisites: Network access to a vulnerable Symantec Antivirus installation · Ability to send a malicious archive file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/91434
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036199
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036198
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40031/

Scores

CVSS v3 8.4
EPSS 0.1810
EPSS Percentile 96.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (27)
symantec/advanced_threat_protection < 2.0.3
symantec/csapi < 10.0.4
symantec/data_center_security_server 6.0 (2 CPE variants)
symantec/data_center_security_server 6.5 (2 CPE variants)
symantec/data_center_security_server 6.6 (2 CPE variants)
symantec/endpoint_protection 12.1.6 mp1 (5 CPE variants)
symantec/mail_security_for_domino 8.0 - 8.0.9
symantec/mail_security_for_microsoft_exchange 6.5.8
symantec/mail_security_for_microsoft_exchange 7.0 - 7.0.4
symantec/message_gateway < 10.6.1-3
... and 17 more
Published Jun 30, 2016
Tracked Since Feb 18, 2026