CVE-2016-3646
Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x から 6.6 MP1; Symantec Web Gateway; 12.1 RU6 MP5 より前の Symantec...
- 公開済み
- 2016/06/30
- 更新済み
- 2024/08/06
- CNA の割り当て
- symantec
- 観察された証拠
- 2016/06/29
プライマリ CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C中 · 今後 30 日間
- パーセンタイル
- 97.6%
- モデルの日付
- 2026/09/21
EPSS は統計的な推定値であり、確実性や影響の尺度ではありません。 CVSS、KEV ステータス、暴露、環境と組み合わせます。
概要
Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x から 6.6 MP1; Symantec Web Gateway; 12.1 RU6 MP5 より前の Symantec Endpoint Protection (SEP); Mac 向け Symantec Endpoint Protection (SEP); 12.1 RU6 MP5 より前の Linux 向け Symantec Endpoint Protection (SEP); 7.0.5 HF01 より前、7.5.3 HF03 より前の 7.5.x、HF01 より前の 7.5.4、および HF01 より前の 7.8.0 の Symantec Protection Engine (SPE); 6.0.5 HF 1.5 より前の 6.0.3 から 6.0.5 まで、および HF 1.6 より前の 6.0.6 の Symantec Protection for SharePoint Servers (SPSS); 7.0_3966002 HF1.1 より前、および 7.5_3966008 VHF1.2 より前の 7.5.x の Symantec Mail Security for Microsoft Exchange (SMSMSE); 8.0.9 HF1.1 より前、および 8.1.3 HF1.2 より前の 8.1.x の Symantec Mail Security for Domino (SMSDOM); 10.0.4 HF01 より前の CSAPI; 10.6.1-4 より前の Symantec Message Gateway (SMG); パッチ 254 より前の 10.5、およびパッチ 253 より前の 10.6 の Symantec Message Gateway for Service Providers (SMG-SP); NGC 22.7 より前の Norton AntiVirus、Norton Security、Norton Internet Security、および Norton 360; 13.0.2 より前の Norton Security for Mac; 5.1 より前の Norton Power Eraser (NPE); 2016.1 より前の Norton Bootable Removal Tool (NBRT) の AntiVirus Decomposer エンジンは、解凍中に不適切に処理される細工された ZIP アーカイブを介して、リモートの攻撃者が任意のコードを実行したり、サービス拒否 (メモリアクセス違反) を引き起こしたりすることを許します。
ソース
1Google Security Research · multiple · 2016/06/29
責任ある使用
脆弱性情報は、自分が所有しているシステム、またはテストを許可されているシステムでのみ使用してください。 Kitploit は公開研究メタデータにリンクしており、エクスプロイト コードや悪意のあるペイロードは保存しません。