Impact
An interactive non‑administrator user can drive a DCOM and task scheduler logic chain in Symantec Management Suite (ITMS) 8.7.3 to obtain full SYSTEM code execution. Because no network access or memory corruption is required, the flaw relies solely on the design of the DCOM/task scheduler integration to elevate privileges. The vulnerability enables an attacker with local access to run arbitrary code with SYSTEM rights, potentially compromising confidentiality, integrity, and availability of the affected machine. The weakness is an incorrect privilege assignment for a critical resource, mapped to CWE‑269.
Affected Systems
Broadcom Symantec Management Suite ITMS version 8.7.3 is affected. The vulnerability is specific to this product and version; no other vendor or product versions are listed.
Risk and Exploitability
The CVSS score of 5.1 places this vulnerability in the moderate severity range. The EPSS score of less than 1% indicates that exploitation is expected to be rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local interactive user exploiting the DCOM/task scheduler chain from within the operating system, without the need for external network reach.
OpenCVE Enrichment