Vulnerability record · CVE-2016-2211 · published 30 June 2016
CVE-2016-2211: Symantec AntiVirus Decomposer CAB parsing memory corruption
Symantec · Mail Security For Microsoft Exchange
The AntiVirus Decomposer engine in numerous Symantec and Norton products mishandles crafted CAB files during decompression, causing a memory buffer overflow (CWE-119). Because the engine is embedded across endpoint, gateway, mail, and consumer products, a single malformed archive can corrupt memory in many scanning paths.
Description
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted CAB file that is mishandled during decompression.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 3.0 is 7.8 High with high confidentiality, integrity, and availability impact, and EPSS is near the top percentile, though no KEV listing or known exploit is documented.
What it is
The AntiVirus Decomposer engine in numerous Symantec and Norton products mishandles crafted CAB files during decompression, causing a memory buffer overflow (CWE-119). Because the engine is embedded across endpoint, gateway, mail, and consumer products, a single malformed archive can corrupt memory in many scanning paths.
Impact
An attacker can execute arbitrary code in the context of the scanning process or crash it, causing a denial of service. On endpoint and gateway products this can mean code execution with the privileges of the antivirus service.
Attack surface
Reached locally per the CVSS vector (AV:L) with no privileges required (PR:N) but requiring user interaction (UI:R), consistent with a crafted CAB file being opened or scanned. The description states remote attackers, so delivery is likely via a file the victim or a scanning service processes.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.534, ~98.9th percentile), and references are only vendor and third-party advisories with no public exploit tag.
What to do
- Apply the vendor fixes listed in Symantec advisory suid=20160628_00 for each affected product line (SEP 12.1 RU6 MP5, SPE 7.0.5 HF01/7.5.3 HF03/7.5.4 HF01/7.8.0 HF01, SMSMSE, SMSDOM, SMG, SPE, CSAPI, and Norton NGC 22.7 or later).
- Inventory all Symantec and Norton products using the Decomposer engine, including mail, gateway, SharePoint, and consumer builds, and confirm each is at or above its fixed build.
- Block or quarantine untrusted CAB archives at mail and web gateways until all scanning engines are patched.
- Where patching is delayed, isolate or restrict scanning services and disable automatic decompression of untrusted archives if the product allows it.
Detection
- Monitor antivirus and gateway service crashes or restarts correlated with CAB file processing.
- Alert on unexpected child processes or code execution originating from Symantec/Norton scanning service processes.
- Search endpoint and mail logs for repeated handling of the same crafted CAB file across hosts.
- Track patch state of the listed Symantec and Norton builds and flag any host still below the fixed version.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/91438 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1036198 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1036199 | Third Party AdvisoryVDB Entry |
| https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year= | Vendor Advisory |
| http://www.securityfocus.com/bid/91438 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1036198 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1036199 | Third Party AdvisoryVDB Entry |
| https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year= | Vendor Advisory |
Track CVE-2016-2211 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-2211), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.