9.3
CVSSv2

CVE-2009-1431

Published: 29/04/2009 Updated: 20/09/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

XFR.EXE in the Intel File Transfer service in the console in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 prior to 9.0 MR7, 10.0 and 10.1 prior to 10.1 MR8, and 10.2 prior to 10.2 MR2; Symantec Client Security (SCS) 2 prior to 2.0 MR7 and 3 prior to 3.1 MR8; and Symantec Endpoint Protection (SEP) prior to 11.0 MR3, allows remote malicious users to execute arbitrary code by placing the code on a (1) share or (2) WebDAV server, and then sending the UNC share pathname to this service.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec client security

symantec endpoint protection

symantec system center

symantec antivirus central quarantine server

symantec antivirus

symantec antivirus -