PT-2004-3512 · Symantec · Altiris Deployment Solution
Publicado
2004-12-31
·
Atualizado
2017-07-20
·
CVE-2004-2622
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Altiris Deployment Solution versions 5.x through 6.x
Description
The issue concerns a lack of required authentication in AClient.exe, allowing remote malicious servers to gain administrator access if they are the first Deployment Server that AClient.exe connects to.
Recommendations
For Altiris Deployment Solution versions 5.x through 6.x, consider implementing additional authentication mechanisms to ensure that only authorized Deployment Servers can connect to AClient.exe. As a temporary workaround, restrict access to AClient.exe to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Altiris Deployment Solution