CVE-2008-2287: High severity symantec deployment solution vulnerability
Published May 18, 2008
·Updated
Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 does not properly protect the install directory, which might allow local users to gain privileges by replacing an application component with a Trojan horse.
Affected Software
2 affected components
Symantec Altiris Deployment Solution=6.9
Symantec Altiris Deployment Solution=6.8
Remediation
Event History
May 18, 2008
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2287?
CVE-2008-2287 is considered a moderate severity vulnerability due to the risk of privilege escalation.
2
How do I fix CVE-2008-2287?
To fix CVE-2008-2287, upgrade to Symantec Altiris Deployment Solution version 6.9.176 or later.
3
What systems are affected by CVE-2008-2287?
CVE-2008-2287 affects Symantec Altiris Deployment Solution versions 6.8 and 6.9 prior to 6.9.176.
4
What is the impact of CVE-2008-2287?
The impact of CVE-2008-2287 is that local users could potentially exploit the vulnerability to gain elevated privileges.
5
Is CVE-2008-2287 exploitable remotely?
CVE-2008-2287 is not remotely exploitable and requires local access to the vulnerable system.