---
id: CVE-2026-15380
title: >-
  A non-administrator interactive user can obtain full SYSTEM code execution
  through a DCOM/task scheduler logic chain — no network access, no memory
  corruption required (ITMS 8.7.3)
summary: >-
  A non-administrator interactive user can obtain full SYSTEM code execution
  through a DCOM/task scheduler logic chain — no network access, no memory
  corruption required (ITMS 8.7.3)
severity: none
published: '2026-07-17'
updated: '2026-07-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15380'
references:
  - url: >-
      https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37995
    label: secure@symantec.com
tags:
  - nvd
epss: 0.00168
epssPercentile: 0.06424
ingestedAt: '2026-07-19T14:31:06.107Z'
---

## Overview

A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
