CVE-2026-15380

Summary

A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)

Affected Software

VendorProductVersion RangeStatus
BroadcomSymantec Management Suitebefore SMA_SMP_8_8_PF_v13 and SMA_SMP_8_8_1_PF_v5affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References