CVE-2008-1473: High severity symantec deployment solution vulnerability
Published Mar 24, 2008
·Updated
The Altiris Client Service (AClient.exe) in Symantec Altiris Deployment Solution 6.8.x before 6.9.164 allows local users to gain privileges via a "Shatter" style attack.
Affected Software
7 affected components
Symantec Altiris Deployment Solution=6.8.282
Symantec Altiris Deployment Solution=6.8-sp2
Symantec Altiris Deployment Solution=6.8.378
Symantec Altiris Deployment Solution=6.8.380.0
Symantec Altiris Deployment Solution=6.8-sp1
Symantec Altiris Deployment Solution=6.8
Symantec Altiris Deployment Solution=6.8.380
Remediation
Event History
Mar 24, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1473?
CVE-2008-1473 is classified as a medium severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2008-1473?
To remediate CVE-2008-1473, upgrading to Symantec Altiris Deployment Solution version 6.9.164 or later is recommended.
3
What are the affected versions for CVE-2008-1473?
CVE-2008-1473 affects versions 6.8 and prior releases of Symantec Altiris Deployment Solution up to 6.8.380.
4
Can CVE-2008-1473 be exploited remotely?
CVE-2008-1473 can only be exploited locally by users with limited privileges.
5
What type of vulnerability is CVE-2008-1473?
CVE-2008-1473 is a local privilege escalation vulnerability that allows unauthorized users to gain higher access.