CVE-2009-3028 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 42.6% (pctl 99)
Patch early
A public exploit exists.
Description
The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 42.6% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-03-07 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| symantec | altiris deployment solution |
| symantec | altiris notification server |
| symantec | management platform |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Symantec Altiris Deployment Solution - ActiveX Control Arbitrary File Download and Execute (Metasploit) | 2010-11-24 |
References
- http://secunia.com/advisories/36679
- http://www.osvdb.org/57893
- http://www.securityfocus.com/bid/36346
- http://www.symantec.com/business/support/index?page=content&id=TECH44885
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090922_00
- http://secunia.com/advisories/36679
- http://www.osvdb.org/57893
- http://www.securityfocus.com/bid/36346
- http://www.symantec.com/business/support/index?page=content&id=TECH44885
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090922_00
→ the Explorer · watch your stack · NVD