CVE-2009-3033

Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
symantecaltiris_deployment_solution
6.9
symantecaltiris_deployment_solution
6.9:sp1
symantecaltiris_deployment_solution
6.9:sp2
symantecaltiris_deployment_solution
6.9:sp3
symantecaltiris_deployment_solution
6.9.164
symantecaltiris_deployment_solution
6.9.176
symantecaltiris_deployment_solution
6.9.355
symantecaltiris_deployment_solution
6.9.355:sp1
symantecaltiris_management_platform
7.0
symantecaltiris_management_platform
7.0:sp1
symantecaltiris_notification_server
6.0
symantecaltiris_notification_server
6.0:sp1
symantecaltiris_notification_server
6.0:sp2
symantecaltiris_notification_server
6.0:sp3
symantecaltiris_notification_server
6.0:sp3_r7
symantecaltiris_notification_server
6.0_sp3:_sp3
𝑥
= Vulnerable software versions