Symantec could have chosen to ship only the minimal filesystem interface code in the kernel and run the huge, complex inspection code in an isolated low-privilege thread, just like the Windows NT guides recommended in 1993.
Symantec could have performed basic diligence and updated their dependencies when security updates were released.
Symantec could have followed recommended practice for code auditing, fuzzing, etc.
In each case they chose not to spend the money it'd take to be minimally competent, correctly realizing that most of their customers will never check and are unlikely to change their buying habits. Based on my experience running their enterprise management tools and dealing with their support, I'm pretty sure someone just made the business decision not to spend the money because most of their customers have audit requirements to buy something and nobody else in the industry is significantly better.