PT-2010-1241 · Symantec · Symantec Workspace Streaming+1
Publicado
2010-06-17
·
Atualizado
2017-08-08
·
CVE-2008-4389
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Symantec AppStream versions 5.2.x
Symantec Workspace Streaming (SWS) versions 6.1.x through 6.1 SP3
Description
The issue concerns improper authentication, allowing remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system and execute them.
Recommendations
For Symantec AppStream version 5.2.x, update to a version that properly performs authentication.
For Symantec Workspace Streaming (SWS) versions 6.1.x through 6.1 SP3, update to version 6.1 SP4 or later to resolve the issue.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Symantec Appstream
Symantec Workspace Streaming