PT-2009-5369 · Symantec · Altiris Express Ns Console Utilities Activex Control+4

Published

2009-11-25

·

Updated

2017-08-17

·

CVE-2009-3033

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Symantec Altiris Deployment Solution versions 6.9.x Symantec Altiris Notification Server versions 6.0.x Symantec Management Platform versions 7.0.x
Description: The issue is related to a buffer overflow in the RunCmd method of the Altiris eXpress NS Console Utilities ActiveX control. This control is part of the web console in Symantec Altiris products. The buffer overflow can be triggered by a long string in the second argument, allowing remote attackers to execute arbitrary code.
Recommendations: For Symantec Altiris Deployment Solution versions 6.9.x, consider disabling the AeXNSConsoleUtilities.dll until a patch is available. For Symantec Altiris Notification Server versions 6.0.x, restrict access to the web console to minimize the risk of exploitation. For Symantec Management Platform versions 7.0.x, avoid using the RunCmd method with untrusted input until the issue is resolved.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3033

Affected Products

Aexnsconsoleutilities.Dll
Altiris Express Ns Console Utilities Activex Control
Symantec Altiris Deployment Solution
Symantec Altiris Notification Server
Symantec Management Platform