peter bassill · operator
$ cve CVE-2009-3028 JSON

CVE-2009-3028 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 42.6% (pctl 99)

Patch early

A public exploit exists.

Description

The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS42.6% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2011-03-07
Last modified2026-06-16

Affected (3)

VendorProduct
symantecaltiris deployment solution
symantecaltiris notification server
symantecmanagement platform

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD