CVE-2016-6590: Symantec Encryption Desktop
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.
Affected products
- Symantec Encryption Desktop: from 10.0.0, before 10.4.1 (fixed in 10.4.1)
- Symantec Endpoint Encryption: from 7.0, before 7.6 (fixed in 7.6); version 7.6 only
- Symantec Ghost Solution Suite: version 3.1 only
- Symantec It Management Suite: version 7.6 only; version 8.0 only
Published 2020-01-08. Last modified 2026-06-17.