Windows DCOM Task Scheduler Logic Chain Allows SYSTEM Execution (ITMS 8.7.3)
CVE-2026-15380 Published on July 17, 2026

Local privilege escalation in Symantec ITMS
A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain no network access, no memory corruption required (ITMS 8.7.3)

Vendor Advisory NVD


Affected Versions

Broadcom Symantec Management Suite Version before SMA_SMP_8_8_PF_v13 and SMA_SMP_8_8_1_PF_v5 is affected by CVE-2026-15380