CVE-2025-9059

HIGH

Altiris Core Agent Updater - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.

Scores

CVSS v4 8.8
EPSS 0.0002
EPSS Percentile 5.5%
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:A/V:C/RE:M/U:Red

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269 CWE-427
Status published
Products (3)
Broadcom/8.6.IT Management Suite 8.6.x
Broadcom/8.6.IT Management Suite 8.7.x
Broadcom/8.6.IT Management Suite 8.8
Published Sep 11, 2025
Tracked Since Feb 18, 2026