6.8

CVE-2009-3028

Exploit
The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Altiris Deployment Solution Version 6.9 Update sp1
Symantec ≫ Altiris Deployment Solution Version 6.9 Update sp2
Symantec ≫ Altiris Deployment Solution Version 6.9 Update sp3
Symantec ≫ Altiris Deployment Solution Version 6.9 Update sp4
Symantec ≫ Altiris Notification Server Version 6.0 Update sp1
Symantec ≫ Altiris Notification Server Version 6.0 Update sp1_hf12
Symantec ≫ Altiris Notification Server Version 6.0 Update sp2
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r1
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r10
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r11
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r12
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r13
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r2
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r3
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r4
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r5
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r6
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r7
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r8
Symantec ≫ Altiris Notification Server Version 6.0 Update sp3_r9
Symantec ≫ Management Platform Version 7.0
Symantec ≫ Management Platform Version 7.0 Update rc5
Symantec ≫ Management Platform Version 7.0 Update sp1
Symantec ≫ Management Platform Version 7.0 Update sp2
Symantec ≫ Management Platform Version 7.0 Update sp3
Symantec ≫ Management Platform Version 7.0 Update sp4
Symantec ≫ Management Platform Version 7.0 Update sp5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 42.6% 0.985
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/36679
Vendor Advisory
http://www.osvdb.org/57893
http://www.securityfocus.com/bid/36346
Exploit
http://www.symantec.com/business/support/index?page=content&id=TECH44885
Patch
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090922_00