CVE-2016-3646
Symantec Advanced Threat Protection (ATP) 中的 AntiVirus Decomposer 引擎;Symantec Data Center Security:Server (SDCS:S) 6.x 至 6.6 MP1;Symantec Web Gateway;12.1...
- 已发布
- 2016年6月30日
- 已更新
- 2024年8月6日
- 分配 CNA
- symantec
- 观察到的证据
- 2016年6月29日
初级CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C中 · 未来 30 天
- 百分位
- 97.6%
- 型号日期
- 2026年9月21日
EPSS 是统计估计,而不是确定性或影响衡量标准。将其与 CVSS、KEV 状态、暴露程度和您的环境相结合。
总结
Symantec Advanced Threat Protection (ATP) 中的 AntiVirus Decomposer 引擎;Symantec Data Center Security:Server (SDCS:S) 6.x 至 6.6 MP1;Symantec Web Gateway;12.1 RU6 MP5 之前的 Symantec Endpoint Protection (SEP);Symantec Endpoint Protection (SEP) for Mac;12.1 RU6 MP5 之前的 Symantec Endpoint Protection (SEP) for Linux;Symantec Protection Engine (SPE):7.0.5 HF01 之前、7.5.3 HF03 之前的 7.5.x、HF01 之前的 7.5.4 以及 HF01 之前的 7.8.0;Symantec Protection for SharePoint Servers (SPSS):6.0.5 HF 1.5 之前的 6.0.3 至 6.0.5 以及 HF 1.6 之前的 6.0.6;Symantec Mail Security for Microsoft Exchange (SMSMSE):7.0_3966002 HF1.1 之前以及 7.5_3966008 VHF1.2 之前的 7.5.x;Symantec Mail Security for Domino (SMSDOM):8.0.9 HF1.1 之前以及 8.1.3 HF1.2 之前的 8.1.x;10.0.4 HF01 之前的 CSAPI;10.6.1-4 之前的 Symantec Message Gateway (SMG);Symantec Message Gateway for Service Providers (SMG-SP):补丁 254 之前的 10.5 以及补丁 253 之前的 10.6;NGC 22.7 之前的 Norton AntiVirus、Norton Security、Norton Internet Security 和 Norton 360;13.0.2 之前的 Norton Security for Mac;5.1 之前的 Norton Power Eraser (NPE);以及 2016.1 之前的 Norton Bootable Removal Tool (NBRT) 允许远程攻击者通过特制的 ZIP 压缩包(在解压过程中处理不当)执行任意代码或造成拒绝服务(内存访问违规)。
来源
1Google Security Research · multiple · 2016年6月29日
负责任的使用
仅在您拥有或有权测试的系统上使用漏洞信息。 Kitploit 链接到公共研究元数据,并且不存储漏洞代码或恶意负载。