Vulnerability record · CVE-2016-5311 · published 9 January 2020
CVE-2016-5311: Symantec endpoint protection uncontrolled search path element vulnerability
Symantec · Endpoint Protection
A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due to a DLL-preloading without path restrictions, which could let a local malicious user obtain system privileges.
Description
A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due to a DLL-preloading without path restrictions, which could let a local malicious user obtain system privileges.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/94295 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1037323 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1037324 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1037325 | Third Party AdvisoryVDB Entry |
| https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year= | Vendor Advisory |
| http://www.securityfocus.com/bid/94295 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1037323 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1037324 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1037325 | Third Party AdvisoryVDB Entry |
| https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year= | Vendor Advisory |
Track CVE-2016-5311 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-5311), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.