CVE-2010-0111

Symantec AntiVirus Corporate Edition < 10.1 MR10 - Remote Code Execution via UNC Share Pathname

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-0111. PoCs published by MC, including Metasploit module exploits/windows/antivirus/ams_hndlrsvc.

AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Symantec System Center Alert Management System (hndlrsvc.exe) by sending a maliciously crafted packet to execute arbitrary commands or deliver a payload via TFTP.

Description

HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote attackers to execute arbitrary programs by sending msgsys.exe a UNC share pathname, which is used directly in a CreateProcessA (aka CreateProcess) call.

Exploits (1)

metasploit WORKING POC EXCELLENT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/antivirus/ams_hndlrsvc.rb

This Metasploit module exploits a command injection vulnerability in Symantec System Center Alert Management System (hndlrsvc.exe) by sending a maliciously crafted packet to execute arbitrary commands or deliver a payload via TFTP.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Symantec AntiVirus Corporate Edition 8.0 - 10.1.7
No auth needed
Prerequisites: Network access to the target on port 38292 · TFTP server for payload delivery if not using direct command execution
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43099
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-11-029
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64943
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43106
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64942
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45935
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0234
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024997

Scores

EPSS 0.3452
EPSS Percentile 98.2%

Details

CWE
CWE-20
Status published
Products (30)
symantec/antivirus 10.0 (3 CPE variants)
symantec/antivirus 10.0.1
symantec/antivirus 10.0.1.1
symantec/antivirus 10.0.1.2
symantec/antivirus 10.0.2
symantec/antivirus 10.0.2.1
symantec/antivirus 10.0.2.2
symantec/antivirus 10.0.3
symantec/antivirus 10.0.4
symantec/antivirus 10.0.5
... and 20 more
Published Jan 31, 2011
Tracked Since Feb 18, 2026