← Back to CVE List
Vulnerability Intelligence Report

CVE-2016-3645

Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to have an unspecified impact via crafted TNEF data.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:24.61%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
symantec norton_security all
symantec protection_engine 7.8.0
symantec advanced_threat_protection all
symantec norton_bootable_removal_tool all
symantec data_center_security_server 6.0, 6.5, 6.6
symantec protection_for_sharepoint_servers all
symantec message_gateway_for_service_providers 10.5, 10.6
symantec csapi all
symantec endpoint_protection 12.1.6
symantec norton_power_eraser all
symantec mail_security_for_domino all
symantec mail_security_for_microsoft_exchange 6.5.8
symantec message_gateway all
symantec norton_360 all
symantec norton_antivirus all
symantec norton_internet_security all
symantec norton_security_with_backup all
symantec ngc all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
24.614%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySymantec - A Division of Broadcom · Vendor · USA
Reserved2016-03-23T00:00:00
Published2016-06-30T23:00:00
Patch Date2016-06-28
Last Updated2024-08-06T00:03:34

LINK COPIED TO CLIPBOARD