Lucene search

K
cve[email protected]CVE-2016-2207
HistoryJun 30, 2016 - 11:59 p.m.

CVE-2016-2207

2016-06-3023:59:01
CWE-20
web.nvd.nist.gov
32
symantec
antivirus
decomposer engine
remote attackers
arbitrary code execution
denial of service
rar file
vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.7 High

AI Score

Confidence

High

0.743 High

EPSS

Percentile

98.2%

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation) via a crafted RAR file that is mishandled during decompression.

Affected configurations

NVD
Node
symantecmail_security_for_microsoft_exchangeRange7.07.0.4
OR
symantecmail_security_for_microsoft_exchangeRange7.57.5.4
OR
symantecmail_security_for_microsoft_exchangeMatch6.5.8
Node
symantecnorton_power_eraserRange5.0
Node
symantecprotection_engineRange7.0.07.0.5
OR
symantecprotection_engineRange7.5.07.5.4
OR
symantecprotection_engineMatch7.8.0
Node
symantecendpoint_protectionMatch12.1.6mp1
OR
symantecendpoint_protectionMatch12.1.6mp1a
OR
symantecendpoint_protectionMatch12.1.6mp2
OR
symantecendpoint_protectionMatch12.1.6mp3
OR
symantecendpoint_protectionMatch12.1.6mp4
Node
symantecmessage_gatewayRange10.6.1-3
Node
symantecnorton_360
OR
symantecnorton_antivirus
OR
symantecnorton_internet_security
OR
symantecnorton_security
OR
symantecnorton_security_with_backup
AND
symantecngcRange22.6
Node
symantecmessage_gateway_for_service_providersMatch10.5
OR
symantecmessage_gateway_for_service_providersMatch10.6
Node
symantecnorton_bootable_removal_toolRange2016.0
Node
symantecmail_security_for_dominoRange8.08.0.9
OR
symantecmail_security_for_dominoRange8.18.1.3
Node
symantecdata_center_security_serverMatch6.0
OR
symantecdata_center_security_serverMatch6.0mp1
OR
symantecdata_center_security_serverMatch6.5
OR
symantecdata_center_security_serverMatch6.5mp1
OR
symantecdata_center_security_serverMatch6.6
OR
symantecdata_center_security_serverMatch6.6mp1
Node
symantecnorton_securityRange13.0.1macos
Node
symantecadvanced_threat_protectionRange2.0.3
Node
symantecprotection_for_sharepoint_serversMatch6.03
OR
symantecprotection_for_sharepoint_serversMatch6.04
OR
symantecprotection_for_sharepoint_serversMatch6.05
OR
symantecprotection_for_sharepoint_serversMatch6.06
Node
symanteccsapiRange10.0.4
Node
symantecendpoint_protectionMatch12.1.6mp1
OR
symantecendpoint_protectionMatch12.1.6mp1a
OR
symantecendpoint_protectionMatch12.1.6mp2
OR
symantecendpoint_protectionMatch12.1.6mp3
OR
symantecendpoint_protectionMatch12.1.6mp4
AND
applemacosMatch-
OR
linuxlinux_kernelMatch-

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.7 High

AI Score

Confidence

High

0.743 High

EPSS

Percentile

98.2%