CVE-2016-2208: Symantec Anti-Virus Engine

Critical severity, CVSS 9.1. EPSS: 19.2% chance of exploitation in the next 30 days.

The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.

Affected products

  • Symantec Anti-Virus Engine: up to and including 20151.1.0.32

Published 2016-05-19. Last modified 2026-06-17.