CVE-2016-2208: Critical severity symantec antivirus vulnerability
Published May 19, 2016
·Updated
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.
Affected Software
1 affected component
Symantec Anti-Virus Engine<=20151.1.0.32
Event History
May 19, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2208?
CVE-2016-2208 has a high severity rating, allowing remote attackers to execute arbitrary code or cause a denial of service.
2
How do I fix CVE-2016-2208?
To fix CVE-2016-2208, update your Symantec Anti-Virus Engine to version 20151.1.1.4 or later.
3
What systems are affected by CVE-2016-2208?
CVE-2016-2208 affects various versions of the Symantec Anti-Virus Engine prior to 20151.1.1.4.
4
What type of vulnerability is CVE-2016-2208?
CVE-2016-2208 is a remote code execution vulnerability stemming from a malformed PE header file.
5
Can CVE-2016-2208 result in a system crash?
Yes, CVE-2016-2208 can cause a system crash due to memory access violations.