Vulnerability CVE-2009-3028


Published: 2011-03-07   Modified: 2012-02-13

Description:
The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Symantec -> Altiris deployment solution 
Symantec -> Altiris notification server 
Symantec -> Management platform 

 References:
http://www.symantec.com/business/support/index?page=content&id=TECH44885
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090922_00
http://www.securityfocus.com/bid/36346
http://www.osvdb.org/57893
http://secunia.com/advisories/36679

Copyright 2020, cxsecurity.com

 

Back to Top