CVE-2009-3109
Symantec Altiris Deployment Solution <6.9 SP3 Build 430 - Auth Bypass
Title source: llmDescription
Unspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication is being used between a deployment server and a client, allows remote attackers to bypass authentication and execute arbitrary commands as SYSTEM by spoofing the deployment server and sending "alternate commands" before the handshake is completed.
References (4)
Core 4
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36502
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/36112
Third Party Advisory x_refsource_confirm
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_00
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1022779
Scores
EPSS
0.0038
EPSS Percentile
59.7%
Details
Status
published
Products (1)
symantec/altiris_deployment_solution
6.9 (3 CPE variants)
Published
Sep 08, 2009
Tracked Since
Feb 18, 2026