Junglewise Threat Intelligence

CVE-2026-15380: Broadcom Symantec Management Suite privilege escalation via DCOM and Task Scheduler

CVE-2026-15380 · Severity: info · CVSS 5.1 · Published 2026-07-17

Executive brief

A security vulnerability in Symantec Management Suite (ITMS) allows a standard user with local access to gain full administrative control over the system. By exploiting a flaw in how the software handles background tasks and system communications, an attacker can execute commands with the highest level of privilege (SYSTEM). This could lead to a complete compromise of the affected machine, allowing for unauthorized data access or persistent control by a malicious actor.

Technical details

A local privilege escalation vulnerability exists in Symantec Management Suite (ITMS) versions 8.7.3, 8.8, and 8.8.1. The flaw resides in a logic chain involving DCOM and the Windows Task Scheduler, which can be manipulated by a non-privileged interactive user. By exploiting this logic, an attacker can bypass security boundaries to execute arbitrary code with SYSTEM privileges without requiring memory corruption or network access. The attack requires local interactive access and some level of user interaction as indicated by the CVSS vector. Broadcom has identified the affected versions, and users are advised to consult the official security advisory for remediation steps.

Affected products

  • Broadcom / Symantec Symantec Management Suite (ITMS) 8.7.3, 8.8, 8.8.1

Timeline

  • 2026-07-17: disclosed: CVE published by Symantec Corporation

References