CVE-2015-8154: Symantec Endpoint Protection Manager
High severity, CVSS 8.8. EPSS: 5% chance of exploitation in the next 30 days.
The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4 allows remote attackers to execute arbitrary code via a crafted HTML document, related to "RWX Permissions."
Affected products
- Symantec Endpoint Protection Manager: up to and including 12.1
Published 2016-03-18. Last modified 2026-06-17.