CVE-2016-2208

CRITICAL

Symantec Anti-virus Engine < 20151.1.0.32 - Resource Management Error

Title source: rule

Description

The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/39835

Scores

CVSS v3 9.1
EPSS 0.5267
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-399
Status published
Products (1)
symantec/anti-virus_engine < 20151.1.0.32
Published May 19, 2016
Tracked Since Feb 18, 2026