PT-2004-3512 · Symantec · Altiris Deployment Solution
Published
2004-12-31
·
Updated
2017-07-20
·
CVE-2004-2622
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Altiris Deployment Solution versions 5.x through 6.x
Description
The issue concerns a lack of required authentication in AClient.exe, allowing remote malicious servers to gain administrator access if they are the first Deployment Server that AClient.exe connects to.
Recommendations
For Altiris Deployment Solution versions 5.x through 6.x, consider implementing additional authentication mechanisms to ensure that only authorized Deployment Servers can connect to AClient.exe. As a temporary workaround, restrict access to AClient.exe to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Altiris Deployment Solution