PT-2011-1303 · Symantec · Symantec Management Platform+2
Published
2011-03-07
·
Updated
2013-02-07
·
CVE-2009-3028
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Symantec Altiris Deployment Solution versions 6.9.x
Symantec Notification Server versions 6.0.x
Symantec Management Platform versions 7.0.x
Description
The issue concerns an unsafe method exposed by the Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll. This allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the
DownloadAndInstall method.Recommendations
For Symantec Altiris Deployment Solution versions 6.9.x, consider disabling the
DownloadAndInstall method until a patch is available.
For Symantec Notification Server versions 6.0.x, restrict access to the AeXNSPkgDLLib.dll library to minimize the risk of exploitation.
For Symantec Management Platform versions 7.0.x, avoid using the DownloadAndInstall method in the affected ActiveX control until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Symantec Altiris Deployment Solution
Symantec Management Platform
Symantec Notification Server