CVE-2010-3268

Intel Alert Management System <11 - DoS

Title source: llm
STIX 2.1

Description

The GetStringAMSHandler function in prgxhndl.dll in hndlrsvc.exe in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (AMS), as used in Symantec Antivirus Corporate Edition 10.1.4.4010 on Windows 2000 SP4 and Symantec Endpoint Protection before 11.x, does not properly validate the CommandLine field of an AMS request, which allows remote attackers to cause a denial of service (application crash) via a crafted request.

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/515191/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43099
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3206
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42593
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024866
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64028
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45936
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0234

Scores

EPSS 0.0875
EPSS Percentile 92.6%

Details

CWE
CWE-20
Status published
Products (7)
intel/intel_alert_management_system
symantec/antivirus 10.1.4.4010
symantec/endpoint_protection 11.0 (7 CPE variants)
symantec/endpoint_protection 11.0.1 (3 CPE variants)
symantec/endpoint_protection 11.0.2 (3 CPE variants)
symantec/endpoint_protection 11.0.4 (3 CPE variants)
symantec/endpoint_protection 11.0.3001
Published Dec 22, 2010
Tracked Since Feb 18, 2026