PT-2009-1239 · Symantec · Symantec Appstream Client

Published

2009-01-20

·

Updated

2009-05-18

·

CVE-2008-4388

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec AppStream Client versions prior to 5.2.2 SP3 MP1
Description The issue is related to the LaunchObj ActiveX control in the launcher.dll component, which does not properly validate downloaded files. This allows remote attackers to execute arbitrary code via the installAppMgr method and other unspecified methods.
Recommendations For Symantec AppStream Client versions prior to 5.2.2 SP3 MP1, update to version 5.2.2 SP3 MP1 or later to resolve the issue. As a temporary workaround, consider restricting access to the installAppMgr method and other vulnerable methods in the LaunchObj ActiveX control until a patch is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4388

Affected Products

Symantec Appstream Client