The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.
https://www.exploit-db.com/exploits/39835/
https://bugs.chromium.org/p/project-zero/issues/detail?id=820