9.3
CVSSv2

CVE-2010-0111

Published: 31/01/2011 Updated: 17/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x prior to 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote malicious users to execute arbitrary programs by sending msgsys.exe a UNC share pathname, which is used directly in a CreateProcessA (aka CreateProcess) call.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec antivirus 10.0

symantec antivirus 10.1

symantec antivirus 10.1.6.1

symantec antivirus 10.1.6

symantec antivirus 10.0.2

symantec antivirus 10.0.4

symantec antivirus 10.0.7

symantec antivirus 10.1.9

symantec antivirus 10.2

symantec antivirus 10.0.1.2

symantec antivirus 10.0.2.1

symantec antivirus 10.0.5

symantec antivirus 10.1.7

symantec antivirus 10.1.8

symantec antivirus 10.1.4

symantec antivirus 10.1.0.1

symantec antivirus 10.0.8

symantec antivirus 10.0.2.2

symantec antivirus 10.0.1

symantec antivirus 10.0.1.1

symantec antivirus 10.1.5.1

symantec antivirus 10.1.5

symantec antivirus 10.1.4.1

symantec antivirus 10.0.3

symantec antivirus 10.0.9

symantec antivirus 10.0.6

symantec system center 10.0

symantec system center 10.1

symantec antivirus central quarantine server 3.6

symantec antivirus central quarantine server 3.5