CVE-2016-2210

Exp

Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code via a crafted file.

公开: 2016-06-30 最后更新: 2026-06-16 分配方: [email protected] 来源: [email protected]

结论预警: CVE-2016-2210 综合评估为高可利用风险(72.6/100):CVSS 技术影响为高级,利用概率偏高(EPSS 11.37%,百分位 95%) 核心证据: 已收录 1 条公开利用参考(Exploit-DB)。 强制指令: 存在公开利用—请排查暴露面、落实缓解措施并优先修补。

风险随态势动态变化;本站持续评估并同步更新本页展示内容。

CVE-2016-2210 的公开 exploit 引用(Exploit-DB)

EDB-ID 来源 类型 公开时间 链接
40032 exploit_db edb 2016-06-29 Exploit-DB ↗

CVE-2016-2210 的 EPSS(利用预测评分)

EPSS 日更估计相对被利用可能性;百分位表示该 CVE 在已评分漏洞中的相对排名(越高表示相对更严重)。

# 日期 旧 EPSS 分数 新 EPSS 分数 变化(新 − 旧)
1 2026-06-15 29.05% 11.37% -17.68%
2 2025-07-01 36.56% 29.05% -7.51%
3 2025-04-25 36.56%

完整 EPSS 历史 (共 11 条)

CVE-2016-2210 的 CVSS 指标

该 CVE 的 CVSS 指标。

底座分 版本 严重度 向量 可利用性 影响 分数来源
7.3 3.0 HIGH
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H 点击展开
攻击向量 (AV:L)
需要先拿到目标主机上的执行面,或依赖其他用户误操作/恶意操作来触发。
攻击复杂度 (AC:L)
前置条件清晰,成功路径稳定,不依赖罕见竞态或苛刻环境。
权限要求 (PR:N)
不必事先登录或提权,匿名会话也可能成为跳板。
用户交互 (UI:N)
无需受害者点击链接、放行宏或安装软件,攻击链可自动走完。
作用域 (S:U)
破坏局限在脆弱组件原本的安全权限与信任域之内。
机密性影响 (C:L)
可能外泄部分字段或样本数据,但难以形成“整库拖走”的局面。
完整性影响 (I:L)
能改局部记录或配置,但尚不致让整站/整库数据整体不可信。
可用性影响 (A:H)
可造成长时间中断、关键事务无法完成,或伴随数据损毁导致难以自愈。
2.5 4.7 [email protected]
9.0 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:C 点击展开
访问路径 (AV:N)
只要路由可达,即可从远端发起利用。
访问复杂度 (AC:L)
步骤短、路径清晰,复现成本低。
认证 (AU:N)
全程无需有效身份。
机密性影响 (C:P)
机密性受到部分损害。
完整性影响 (I:P)
完整性受到部分损害。
可用性影响 (A:C)
可用性被完全破坏。
10.0 8.5 [email protected]

CVE-2016-2210 的弱点枚举

CVE-2016-2210 的影响软件 / 配置

厂商 产品 版本 原始 CPE
symantec mail_security_for_microsoft_exchange >= 7.0, <= 7.0.4 cpe:2.3:a:symantec:mail_security_for_microsoft_exchange:*:*:*:*:*:*:*:*
symantec mail_security_for_microsoft_exchange >= 7.5, <= 7.5.4 cpe:2.3:a:symantec:mail_security_for_microsoft_exchange:*:*:*:*:*:*:*:*
symantec mail_security_for_microsoft_exchange 6.5.8 cpe:2.3:a:symantec:mail_security_for_microsoft_exchange:6.5.8:*:*:*:*:*:*:*
symantec norton_power_eraser <= 5.0 cpe:2.3:a:symantec:norton_power_eraser:*:*:*:*:*:*:*:*
symantec protection_engine >= 7.0.0, <= 7.0.5 cpe:2.3:a:symantec:protection_engine:*:*:*:*:*:*:*:*
symantec protection_engine >= 7.5.0, <= 7.5.4 cpe:2.3:a:symantec:protection_engine:*:*:*:*:*:*:*:*
symantec protection_engine 7.8.0 cpe:2.3:a:symantec:protection_engine:7.8.0:*:*:*:*:*:*:*
symantec endpoint_protection 12.1.6 cpe:2.3:a:symantec:endpoint_protection:12.1.6:mp1:*:*:*:*:*:*
symantec endpoint_protection 12.1.6 cpe:2.3:a:symantec:endpoint_protection:12.1.6:mp1a:*:*:*:*:*:*
symantec endpoint_protection 12.1.6 cpe:2.3:a:symantec:endpoint_protection:12.1.6:mp2:*:*:*:*:*:*
symantec endpoint_protection 12.1.6 cpe:2.3:a:symantec:endpoint_protection:12.1.6:mp3:*:*:*:*:*:*
symantec endpoint_protection 12.1.6 cpe:2.3:a:symantec:endpoint_protection:12.1.6:mp4:*:*:*:*:*:*
symantec message_gateway <= 10.6.1-3 cpe:2.3:a:symantec:message_gateway:*:*:*:*:*:*:*:*
symantec norton_360 cpe:2.3:a:symantec:norton_360:*:*:*:*:*:*:*:*
symantec norton_antivirus cpe:2.3:a:symantec:norton_antivirus:*:*:*:*:*:*:*:*
symantec norton_internet_security cpe:2.3:a:symantec:norton_internet_security:*:*:*:*:*:*:*:*
symantec norton_security cpe:2.3:a:symantec:norton_security:*:*:*:*:*:*:*:*
symantec norton_security_with_backup cpe:2.3:a:symantec:norton_security_with_backup:*:*:*:*:*:*:*:*
symantec ngc <= 22.6 cpe:2.3:a:symantec:ngc:*:*:*:*:*:*:*:*
symantec message_gateway_for_service_providers 10.5 cpe:2.3:a:symantec:message_gateway_for_service_providers:10.5:*:*:*:*:*:*:*
symantec message_gateway_for_service_providers 10.6 cpe:2.3:a:symantec:message_gateway_for_service_providers:10.6:*:*:*:*:*:*:*
symantec norton_bootable_removal_tool <= 2016.0 cpe:2.3:a:symantec:norton_bootable_removal_tool:*:*:*:*:*:*:*:*
symantec mail_security_for_domino >= 8.0, <= 8.0.9 cpe:2.3:a:symantec:mail_security_for_domino:*:*:*:*:*:*:*:*
symantec mail_security_for_domino >= 8.1, <= 8.1.3 cpe:2.3:a:symantec:mail_security_for_domino:*:*:*:*:*:*:*:*
symantec data_center_security_server 6.0 cpe:2.3:a:symantec:data_center_security_server:6.0:*:*:*:*:*:*:*
symantec data_center_security_server 6.0 cpe:2.3:a:symantec:data_center_security_server:6.0:mp1:*:*:*:*:*:*
symantec data_center_security_server 6.5 cpe:2.3:a:symantec:data_center_security_server:6.5:*:*:*:*:*:*:*
symantec data_center_security_server 6.5 cpe:2.3:a:symantec:data_center_security_server:6.5:mp1:*:*:*:*:*:*
symantec data_center_security_server 6.6 cpe:2.3:a:symantec:data_center_security_server:6.6:*:*:*:*:*:*:*
symantec data_center_security_server 6.6 cpe:2.3:a:symantec:data_center_security_server:6.6:mp1:*:*:*:*:*:*
symantec norton_security <= 13.0.1 cpe:2.3:a:symantec:norton_security:*:*:*:*:*:macos:*:*
symantec advanced_threat_protection <= 2.0.3 cpe:2.3:a:symantec:advanced_threat_protection:*:*:*:*:*:*:*:*
symantec protection_for_sharepoint_servers 6.03 cpe:2.3:a:symantec:protection_for_sharepoint_servers:6.03:*:*:*:*:*:*:*
symantec protection_for_sharepoint_servers 6.04 cpe:2.3:a:symantec:protection_for_sharepoint_servers:6.04:*:*:*:*:*:*:*
symantec protection_for_sharepoint_servers 6.05 cpe:2.3:a:symantec:protection_for_sharepoint_servers:6.05:*:*:*:*:*:*:*
symantec protection_for_sharepoint_servers 6.06 cpe:2.3:a:symantec:protection_for_sharepoint_servers:6.06:*:*:*:*:*:*:*
symantec csapi <= 10.0.4 cpe:2.3:a:symantec:csapi:*:*:*:*:*:*:*:*

CVE-2016-2210 的参考链接

cvelogic Threat Intelligence