CVE-2009-3033
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 40%
from disclosure to weapon165 days
Published on NVDNov 25
1st PoC+165d
metasploitNov 4
exploitation probability
40%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16528unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/60496https://exchange.xforce.ibmcloud.com/vulnerabilities/54415https://kb.altiris.com/article.asp?article=50072&p=1https://kb.altiris.com/article.asp?article=50279&p=1http://www.securityfocus.com/bid/37092http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20091124_00http://www.vupen.com/english/advisories/2009/3328