vulnerability
Symantec Endpoint Protection: CVE-2016-3646: ZIP decompression memory access violation
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 9 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Jun 28, 2016 | Apr 27, 2018 | Oct 5, 2021 |
Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Jun 28, 2016
Added
Apr 27, 2018
Modified
Oct 5, 2021
Description
The AntiVirus Decomposer engine in Symantec Endpoint Protection (SEP) allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation) via a crafted ZIP archive that is mishandled during decompression.
Solution
endpoint_protection-upgrade-latest
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.