CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
5.2%
The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a “Shatter” style attack on the “command prompt” hidden GUI button to (1) overwrite the CommandLine parameter to cmd.exe to use SYSTEM privileges and (2) modify the DLL that is loaded using the LoadLibrary API function.
Vendor | Product | Version | CPE |
---|---|---|---|
symantec | altiris_deployment_solution | * | cpe:2.3:a:symantec:altiris_deployment_solution:*:*:*:*:*:*:*:* |
symantec | altiris_deployment_solution | 6.9.355 | cpe:2.3:a:symantec:altiris_deployment_solution:6.9.355:-:*:*:*:*:*:* |
marc.info/?l=bugtraq&m=122460544316205&w=2
osvdb.org/49426
secunia.com/advisories/31773
www.insomniasec.com/advisories/ISVA-081020.1.htm
www.securityfocus.com/bid/31766
www.securitytracker.com/id?1021071
www.symantec.com/avcenter/security/Content/2008.10.20a.html
www.vupen.com/english/advisories/2008/2876
exchange.xforce.ibmcloud.com/vulnerabilities/46006
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
5.2%