← Vulnerability feed

Vulnerability record · CVE-2016-2211 · published 30 June 2016

CVE-2016-2211: Symantec AntiVirus Decomposer CAB parsing memory corruption

Symantec · Mail Security For Microsoft Exchange

The AntiVirus Decomposer engine in numerous Symantec and Norton products mishandles crafted CAB files during decompression, causing a memory buffer overflow (CWE-119). Because the engine is embedded across endpoint, gateway, mail, and consumer products, a single malformed archive can corrupt memory in many scanning paths.

7.8 CVSS 3.0 High EPSS 53% · top 1.0% CWE-119 · Memory buffer overflow
7.8CVSS 3.0 base score, v2 9.3
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
18Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted CAB file that is mishandled during decompression.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 3.0 is 7.8 High with high confidentiality, integrity, and availability impact, and EPSS is near the top percentile, though no KEV listing or known exploit is documented.

What it is

The AntiVirus Decomposer engine in numerous Symantec and Norton products mishandles crafted CAB files during decompression, causing a memory buffer overflow (CWE-119). Because the engine is embedded across endpoint, gateway, mail, and consumer products, a single malformed archive can corrupt memory in many scanning paths.

Impact

An attacker can execute arbitrary code in the context of the scanning process or crash it, causing a denial of service. On endpoint and gateway products this can mean code execution with the privileges of the antivirus service.

Attack surface

Reached locally per the CVSS vector (AV:L) with no privileges required (PR:N) but requiring user interaction (UI:R), consistent with a crafted CAB file being opened or scanned. The description states remote attackers, so delivery is likely via a file the victim or a scanning service processes.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.534, ~98.9th percentile), and references are only vendor and third-party advisories with no public exploit tag.

What to do

  • Apply the vendor fixes listed in Symantec advisory suid=20160628_00 for each affected product line (SEP 12.1 RU6 MP5, SPE 7.0.5 HF01/7.5.3 HF03/7.5.4 HF01/7.8.0 HF01, SMSMSE, SMSDOM, SMG, SPE, CSAPI, and Norton NGC 22.7 or later).
  • Inventory all Symantec and Norton products using the Decomposer engine, including mail, gateway, SharePoint, and consumer builds, and confirm each is at or above its fixed build.
  • Block or quarantine untrusted CAB archives at mail and web gateways until all scanning engines are patched.
  • Where patching is delayed, isolate or restrict scanning services and disable automatic decompression of untrusted archives if the product allows it.

Detection

  • Monitor antivirus and gateway service crashes or restarts correlated with CAB file processing.
  • Alert on unexpected child processes or code execution originating from Symantec/Norton scanning service processes.
  • Search endpoint and mail logs for repeated handling of the same crafted CAB file across hosts.
  • Track patch state of the listed Symantec and Norton builds and flag any host still below the fixed version.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-2211 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0108Symantec antivirus memory buffer overflow vulnerabilityBuffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9…EPSS 19%10.0CVE-2009-1429Symantec AMS2 Intel LANDesk CBA Remote Command ExecutionThe Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2) passes crafted packet contents directly to the CreateProcessA …EPSS 88%analysed9.8CVE-2016-3645Symantec norton security vulnerabilityInteger overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…EPSS 25%9.3CVE-2012-4953Symantec antivirus memory buffer overflow vulnerabilityThe decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corpor…EPSS 6.0%9.3CVE-2012-0295Symantec endpoint protection code injection vulnerabilityThe Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-…EPSS 4.0%9.3CVE-2009-1430Symantec Alert Management System IAO.EXE stack buffer overflowIAO.EXE in the Symantec Alert Originator Service (Alert Management System 2, shipped with System Center, AntiVirus, Client Security and Endpoint Prot…EPSS 55%analysed9.3CVE-2009-1431Symantec antivirus vulnerabilityXFR.EXE in the Intel File Transfer service in the console in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Syma…EPSS 8.0%8.8CVE-2018-5237Symantec endpoint protection vulnerabilitySymantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of is…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2016-2211), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.