peter bassill · operator
$ cve CVE-2009-3033 JSON

CVE-2009-3033 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 40% (pctl 99)

Patch early

A public exploit exists.

Description

Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS39.97% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2009-11-25
Last modified2026-06-16

Affected (3)

VendorProduct
symantecaltiris deployment solution
symantecaltiris management platform
symantecaltiris notification server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD