6.8

CVE-2009-3028

Exploit

The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.

Data is provided by the National Vulnerability Database (NVD)
SymantecAltiris Deployment Solution Version6.9 Updatesp1
SymantecAltiris Deployment Solution Version6.9 Updatesp2
SymantecAltiris Deployment Solution Version6.9 Updatesp3
SymantecAltiris Deployment Solution Version6.9 Updatesp4
SymantecAltiris Notification Server Version6.0 Updatesp1
SymantecAltiris Notification Server Version6.0 Updatesp1_hf12
SymantecAltiris Notification Server Version6.0 Updatesp2
SymantecAltiris Notification Server Version6.0 Updatesp3
SymantecAltiris Notification Server Version6.0 Updatesp3_r1
SymantecAltiris Notification Server Version6.0 Updatesp3_r10
SymantecAltiris Notification Server Version6.0 Updatesp3_r11
SymantecAltiris Notification Server Version6.0 Updatesp3_r12
SymantecAltiris Notification Server Version6.0 Updatesp3_r13
SymantecAltiris Notification Server Version6.0 Updatesp3_r2
SymantecAltiris Notification Server Version6.0 Updatesp3_r3
SymantecAltiris Notification Server Version6.0 Updatesp3_r4
SymantecAltiris Notification Server Version6.0 Updatesp3_r5
SymantecAltiris Notification Server Version6.0 Updatesp3_r6
SymantecAltiris Notification Server Version6.0 Updatesp3_r7
SymantecAltiris Notification Server Version6.0 Updatesp3_r8
SymantecAltiris Notification Server Version6.0 Updatesp3_r9
SymantecManagement Platform Version7.0
SymantecManagement Platform Version7.0 Updaterc5
SymantecManagement Platform Version7.0 Updatesp1
SymantecManagement Platform Version7.0 Updatesp2
SymantecManagement Platform Version7.0 Updatesp3
SymantecManagement Platform Version7.0 Updatesp4
SymantecManagement Platform Version7.0 Updatesp5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 72.03% 0.986
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P