CVE-2016-2210
Symantec 高级威胁防护 (ATP) 的防病毒分解器引擎中的 Dec2LHA.dll 存在缓冲区溢出漏洞;Symantec Data Center Security:Server (SDCS:S) 6.x 至 6.6 MP1;Symantec Web Gateway;Symantec Endpoint...
- 已发布
- 2016年6月30日
- 已更新
- 2024年8月5日
- 分配 CNA
- symantec
- 观察到的证据
- 2016年6月29日
初级CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:C中 · 未来 30 天
- 百分位
- 97.6%
- 型号日期
- 2026年9月21日
EPSS 是统计估计,而不是确定性或影响衡量标准。将其与 CVSS、KEV 状态、暴露程度和您的环境相结合。
总结
Symantec 高级威胁防护 (ATP) 的防病毒分解器引擎中的 Dec2LHA.dll 存在缓冲区溢出漏洞;Symantec Data Center Security:Server (SDCS:S) 6.x 至 6.6 MP1;Symantec Web Gateway;Symantec Endpoint Protection (SEP) 12.1 RU6 MP5 之前版本;Symantec Endpoint Protection (SEP) for Mac;Symantec Endpoint Protection (SEP) for Linux 12.1 RU6 MP5 之前版本;Symantec Protection Engine (SPE) 7.0.5 HF01 之前版本、7.5.x 7.5.3 HF03 之前版本、7.5.4 HF01 之前版本以及 7.8.0 HF01 之前版本;Symantec Protection for SharePoint Servers (SPSS) 6.0.3 至 6.0.5(6.0.5 HF 1.5 之前)以及 6.0.6(HF 1.6 之前);Symantec Mail Security for Microsoft Exchange (SMSMSE) 7.0_3966002 HF1.1 之前版本和 7.5.x 7.5_3966008 VHF1.2 之前版本;Symantec Mail Security for Domino (SMSDOM) 8.0.9 HF1.1 之前版本和 8.1.x 8.1.3 HF1.2 之前版本;CSAPI 10.0.4 HF01 之前版本;Symantec Message Gateway (SMG) 10.6.1-4 之前版本;Symantec Message Gateway for Service Providers (SMG-SP) 10.5(补丁 254 之前)和 10.6(补丁 253 之前);Norton AntiVirus、Norton Security、Norton Internet Security 和 Norton 360(NGC 22.7 之前版本);Norton Security for Mac 13.0.2 之前版本;Norton Power Eraser (NPE) 5.1 之前版本;以及 Norton Bootable Removal Tool (NBRT) 2016.1 之前版本允许远程攻击者通过特制文件执行任意代码。
来源
1Google Security Research · multiple · 2016年6月29日
负责任的使用
仅在您拥有或有权测试的系统上使用漏洞信息。 Kitploit 链接到公共研究元数据,并且不存储漏洞代码或恶意负载。