The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corporate Edition (SAVCE) 10.x, and Symantec Scan Engine (SSE) before 5.2.8 does not properly perform bounds checks of the contents of CAB archives, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Endpoint_protection | — | Run LiveUpdate(SEP 11.0 or 12.0 SBE clients: Download updated Decomposer engine via Symantec LiveUpdate) or, Upgrade to SEP 12.1 or later. | Apr 27, 2017 | Nov 14, 2012 |
| Symantec_endpoint_protection | — | Upgrade to the latest version of Symantec Endpoint Protection | May 13, 2026 | Nov 14, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub