PT-2010-1241 · Symantec · Symantec Workspace Streaming+1

Published

2010-06-17

·

Updated

2017-08-08

·

CVE-2008-4389

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec AppStream versions 5.2.x Symantec Workspace Streaming (SWS) versions 6.1.x through 6.1 SP3
Description The issue concerns improper authentication, allowing remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system and execute them.
Recommendations For Symantec AppStream version 5.2.x, update to a version that properly performs authentication. For Symantec Workspace Streaming (SWS) versions 6.1.x through 6.1 SP3, update to version 6.1 SP4 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4389

Affected Products

Symantec Appstream
Symantec Workspace Streaming