CVE-2015-4523: Symantec Malware Analysis Appliance

Critical severity, CVSS 9.3. EPSS: 4.5% chance of exploitation in the next 30 days.

Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanism and consequently write to arbitrary files, cause a denial of service (host reboot or reset to factory defaults), or execute arbitrary code via vectors related to saving files during analysis.

Affected products

  • Symantec Malware Analysis Appliance: up to and including 4.2
  • Symantec Malware Analyzer g2: up to and including 3.5

Published 2017-09-11. Last modified 2026-06-17.