PT-2004-3512 · Symantec · Altiris Deployment Solution

Published

2004-12-31

·

Updated

2017-07-20

·

CVE-2004-2622

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Altiris Deployment Solution versions 5.x through 6.x
Description The issue concerns a lack of required authentication in AClient.exe, allowing remote malicious servers to gain administrator access if they are the first Deployment Server that AClient.exe connects to.
Recommendations For Altiris Deployment Solution versions 5.x through 6.x, consider implementing additional authentication mechanisms to ensure that only authorized Deployment Servers can connect to AClient.exe. As a temporary workaround, restrict access to AClient.exe to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2622

Affected Products

Altiris Deployment Solution