CVE-2016-2210
Symantec Advanced Threat Protection (ATP) の AntiVirus Decomposer エンジン内の Dec2LHA.dll...
- 公開済み
- 2016/06/30
- 更新済み
- 2024/08/05
- CNA の割り当て
- symantec
- 観察された証拠
- 2016/06/29
プライマリ CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:C中 · 今後 30 日間
- パーセンタイル
- 97.6%
- モデルの日付
- 2026/09/21
EPSS は統計的な推定値であり、確実性や影響の尺度ではありません。 CVSS、KEV ステータス、暴露、環境と組み合わせます。
概要
Symantec Advanced Threat Protection (ATP) の AntiVirus Decomposer エンジン内の Dec2LHA.dll におけるバッファオーバーフローにより、リモートの攻撃者が巧妙に細工されたファイルを介して任意のコードを実行できる可能性があります。影響を受ける製品は以下のとおりです: Symantec Data Center Security:Server (SDCS:S) 6.x から 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) 12.1 RU6 MP5 より前; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux 12.1 RU6 MP5 より前; Symantec Protection Engine (SPE) 7.0.5 HF01 より前、7.5.x 7.5.3 HF03 より前、7.5.4 HF01 より前、および 7.8.0 HF01 より前; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 から 6.0.5 の 6.0.5 HF 1.5 より前、および 6.0.6 の HF 1.6 より前; Symantec Mail Security for Microsoft Exchange (SMSMSE) 7.0_3966002 HF1.1 より前、および 7.5.x の 7.5_3966008 VHF1.2 より前; Symantec Mail Security for Domino (SMSDOM) 8.0.9 HF1.1 より前、および 8.1.x の 8.1.3 HF1.2 より前; CSAPI 10.0.4 HF01 より前; Symantec Message Gateway (SMG) 10.6.1-4 より前; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 パッチ 254 より前、および 10.6 パッチ 253 より前; Norton AntiVirus、Norton Security、Norton Internet Security、および Norton 360 の NGC 22.7 より前; Norton Security for Mac 13.0.2 より前; Norton Power Eraser (NPE) 5.1 より前; および Norton Bootable Removal Tool (NBRT) 2016.1 より前。
ソース
1Google Security Research · multiple · 2016/06/29
責任ある使用
脆弱性情報は、自分が所有しているシステム、またはテストを許可されているシステムでのみ使用してください。 Kitploit は公開研究メタデータにリンクしており、エクスプロイト コードや悪意のあるペイロードは保存しません。