CVE-2016-2210

Exp

Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code via a crafted file.

Published: 2016-06-30 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2016-2210 is rated High Exploit Risk (72.9/100): CVSS High severity, with high exploitation likelihood (EPSS 29.05%, 96th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2016-2210

EDB-ID Source Kind Published Link
40032 exploit_db edb 2016-06-29 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2016-2210

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-07-01 36.56% 29.05% -7.51%
2 2025-04-25 39.16% 36.56% -2.60%
3 2025-03-30 39.16%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2016-2210

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.3 3.0 HIGH
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.5 4.7 [email protected]
9.0 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 8.5 [email protected]

Weakness enumeration for CVE-2016-2210

Affected software / configurations for CVE-2016-2210

Vendor Product Version Raw CPE
symantec mail_security_for_microsoft_exchange >= 7.0, <= 7.0.4 cpe:2.3:a:symantec:mail_security_for_microsoft_exchange:*:*:*:*:*:*:*:*
symantec mail_security_for_microsoft_exchange >= 7.5, <= 7.5.4 cpe:2.3:a:symantec:mail_security_for_microsoft_exchange:*:*:*:*:*:*:*:*
symantec mail_security_for_microsoft_exchange 6.5.8 cpe:2.3:a:symantec:mail_security_for_microsoft_exchange:6.5.8:*:*:*:*:*:*:*
symantec norton_power_eraser <= 5.0 cpe:2.3:a:symantec:norton_power_eraser:*:*:*:*:*:*:*:*
symantec protection_engine >= 7.0.0, <= 7.0.5 cpe:2.3:a:symantec:protection_engine:*:*:*:*:*:*:*:*
symantec protection_engine >= 7.5.0, <= 7.5.4 cpe:2.3:a:symantec:protection_engine:*:*:*:*:*:*:*:*
symantec protection_engine 7.8.0 cpe:2.3:a:symantec:protection_engine:7.8.0:*:*:*:*:*:*:*
symantec endpoint_protection 12.1.6 cpe:2.3:a:symantec:endpoint_protection:12.1.6:mp1:*:*:*:*:*:*
symantec endpoint_protection 12.1.6 cpe:2.3:a:symantec:endpoint_protection:12.1.6:mp1a:*:*:*:*:*:*
symantec endpoint_protection 12.1.6 cpe:2.3:a:symantec:endpoint_protection:12.1.6:mp2:*:*:*:*:*:*
symantec endpoint_protection 12.1.6 cpe:2.3:a:symantec:endpoint_protection:12.1.6:mp3:*:*:*:*:*:*
symantec endpoint_protection 12.1.6 cpe:2.3:a:symantec:endpoint_protection:12.1.6:mp4:*:*:*:*:*:*
symantec message_gateway <= 10.6.1-3 cpe:2.3:a:symantec:message_gateway:*:*:*:*:*:*:*:*
symantec norton_360 cpe:2.3:a:symantec:norton_360:*:*:*:*:*:*:*:*
symantec norton_antivirus cpe:2.3:a:symantec:norton_antivirus:*:*:*:*:*:*:*:*
symantec norton_internet_security cpe:2.3:a:symantec:norton_internet_security:*:*:*:*:*:*:*:*
symantec norton_security cpe:2.3:a:symantec:norton_security:*:*:*:*:*:*:*:*
symantec norton_security_with_backup cpe:2.3:a:symantec:norton_security_with_backup:*:*:*:*:*:*:*:*
symantec ngc <= 22.6 cpe:2.3:a:symantec:ngc:*:*:*:*:*:*:*:*
symantec message_gateway_for_service_providers 10.5 cpe:2.3:a:symantec:message_gateway_for_service_providers:10.5:*:*:*:*:*:*:*
symantec message_gateway_for_service_providers 10.6 cpe:2.3:a:symantec:message_gateway_for_service_providers:10.6:*:*:*:*:*:*:*
symantec norton_bootable_removal_tool <= 2016.0 cpe:2.3:a:symantec:norton_bootable_removal_tool:*:*:*:*:*:*:*:*
symantec mail_security_for_domino >= 8.0, <= 8.0.9 cpe:2.3:a:symantec:mail_security_for_domino:*:*:*:*:*:*:*:*
symantec mail_security_for_domino >= 8.1, <= 8.1.3 cpe:2.3:a:symantec:mail_security_for_domino:*:*:*:*:*:*:*:*
symantec data_center_security_server 6.0 cpe:2.3:a:symantec:data_center_security_server:6.0:*:*:*:*:*:*:*
symantec data_center_security_server 6.0 cpe:2.3:a:symantec:data_center_security_server:6.0:mp1:*:*:*:*:*:*
symantec data_center_security_server 6.5 cpe:2.3:a:symantec:data_center_security_server:6.5:*:*:*:*:*:*:*
symantec data_center_security_server 6.5 cpe:2.3:a:symantec:data_center_security_server:6.5:mp1:*:*:*:*:*:*
symantec data_center_security_server 6.6 cpe:2.3:a:symantec:data_center_security_server:6.6:*:*:*:*:*:*:*
symantec data_center_security_server 6.6 cpe:2.3:a:symantec:data_center_security_server:6.6:mp1:*:*:*:*:*:*
symantec norton_security <= 13.0.1 cpe:2.3:a:symantec:norton_security:*:*:*:*:*:macos:*:*
symantec advanced_threat_protection <= 2.0.3 cpe:2.3:a:symantec:advanced_threat_protection:*:*:*:*:*:*:*:*
symantec protection_for_sharepoint_servers 6.03 cpe:2.3:a:symantec:protection_for_sharepoint_servers:6.03:*:*:*:*:*:*:*
symantec protection_for_sharepoint_servers 6.04 cpe:2.3:a:symantec:protection_for_sharepoint_servers:6.04:*:*:*:*:*:*:*
symantec protection_for_sharepoint_servers 6.05 cpe:2.3:a:symantec:protection_for_sharepoint_servers:6.05:*:*:*:*:*:*:*
symantec protection_for_sharepoint_servers 6.06 cpe:2.3:a:symantec:protection_for_sharepoint_servers:6.06:*:*:*:*:*:*:*
symantec csapi <= 10.0.4 cpe:2.3:a:symantec:csapi:*:*:*:*:*:*:*:*

References for CVE-2016-2210

cvelogic Threat Intelligence