CVE-2009-3108
08.09.2009, 23:30
The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyone:Full Control), which allows local users to gain privileges by replacing the executable with a Trojan horse program.Enginsight
Vendor | Product | Version |
---|---|---|
symantec | altiris_deployment_solution | 6.9 |
symantec | altiris_deployment_solution | 6.9:sp1 |
symantec | altiris_deployment_solution | 6.9.164 |
symantec | altiris_deployment_solution | 6.9.176 |
symantec | altiris_deployment_solution | 6.9.355 |
symantec | altiris_deployment_solution | 6.9.355:sp1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References