CVE-2016-2208
CRITICALSymantec Anti-Virus Engine < 20151.1.0.32 - Remote Code Execution via Malformed PE Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-2208. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a buffer overflow in Symantec's antivirus engine when parsing executables packed with an early version of aspack. The vulnerability allows remote code execution by triggering a heap or kernel memory corruption via a maliciously crafted file.
Description
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.
Exploits (1)
This exploit leverages a buffer overflow in Symantec's antivirus engine when parsing executables packed with an early version of aspack. The vulnerability allows remote code execution by triggering a heap or kernel memory corruption via a maliciously crafted file.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H