PT-2009-1239 · Symantec · Symantec Appstream Client

Publicado

2009-01-20

·

Atualizado

2009-05-18

·

CVE-2008-4388

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec AppStream Client versions prior to 5.2.2 SP3 MP1
Description The issue is related to the LaunchObj ActiveX control in the launcher.dll component, which does not properly validate downloaded files. This allows remote attackers to execute arbitrary code via the installAppMgr method and other unspecified methods.
Recommendations For Symantec AppStream Client versions prior to 5.2.2 SP3 MP1, update to version 5.2.2 SP3 MP1 or later to resolve the issue. As a temporary workaround, consider restricting access to the installAppMgr method and other vulnerable methods in the LaunchObj ActiveX control until a patch is applied.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4388

Produtos afetados

Symantec Appstream Client