CVE-2009-3033 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 40% (pctl 99)
Patch early
A public exploit exists.
Description
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 39.97% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-11-25 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| symantec | altiris deployment solution |
| symantec | altiris management platform |
| symantec | altiris notification server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Symantec Altiris Deployment Solution - ActiveX Control Buffer Overflow (Metasploit) | 2010-05-09 |
References
- http://osvdb.org/60496
- http://www.securityfocus.com/bid/37092
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20091124_00
- http://www.vupen.com/english/advisories/2009/3328
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54415
- https://kb.altiris.com/article.asp?article=50072&p=1
- https://kb.altiris.com/article.asp?article=50279&p=1
- http://osvdb.org/60496
- http://www.securityfocus.com/bid/37092
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20091124_00
- http://www.vupen.com/english/advisories/2009/3328
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54415
- https://kb.altiris.com/article.asp?article=50072&p=1
- https://kb.altiris.com/article.asp?article=50279&p=1
→ the Explorer · watch your stack · NVD