9.3
CVSSv2

CVE-2009-3033

Published: 25/11/2009 Updated: 17/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote malicious users to execute arbitrary code via a long string in the second argument.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec altiris deployment solution 6.9

symantec altiris deployment solution 6.9.355

symantec altiris management platform 7.0

symantec altiris notification server 6.0

symantec altiris deployment solution 6.9.164

symantec altiris deployment solution 6.9.176

symantec altiris notification server 6.0_sp3

Exploits

## # $Id: symantec_altirisdeployment_runcmdrb 9262 2010-05-09 17:45:00Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require ...