CVE-2009-3108

Symantec Altiris Deployment Solution < 6.9 SP3 Build 430 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyone:Full Control), which allows local users to gain privileges by replacing the executable with a Trojan horse program.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36111
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36502
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022779

Scores

EPSS 0.0004
EPSS Percentile 13.1%

Details

CWE
CWE-264
Status published
Products (4)
symantec/altiris_deployment_solution 6.9 (2 CPE variants)
symantec/altiris_deployment_solution 6.9.164
symantec/altiris_deployment_solution 6.9.176
symantec/altiris_deployment_solution 6.9.355 (2 CPE variants)
Published Sep 08, 2009
Tracked Since Feb 18, 2026