PT-2011-1303 · Symantec · Symantec Management Platform+2

Published

2011-03-07

·

Updated

2013-02-07

·

CVE-2009-3028

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Symantec Altiris Deployment Solution versions 6.9.x Symantec Notification Server versions 6.0.x Symantec Management Platform versions 7.0.x
Description The issue concerns an unsafe method exposed by the Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll. This allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.
Recommendations For Symantec Altiris Deployment Solution versions 6.9.x, consider disabling the DownloadAndInstall method until a patch is available. For Symantec Notification Server versions 6.0.x, restrict access to the AeXNSPkgDLLib.dll library to minimize the risk of exploitation. For Symantec Management Platform versions 7.0.x, avoid using the DownloadAndInstall method in the affected ActiveX control until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-3028

Affected Products

Symantec Altiris Deployment Solution
Symantec Management Platform
Symantec Notification Server