CVE-2009-3028: Medium severity symantec deployment solution vulnerability
The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3028?
CVE-2009-3028 is classified as a critical vulnerability allowing remote code execution.
How do I fix CVE-2009-3028?
To fix CVE-2009-3028, upgrade to the latest version of Symantec Altiris Deployment Solution, Notification Server, or Management Platform.
Which software is affected by CVE-2009-3028?
CVE-2009-3028 affects various versions of Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x.
What kind of attack can result from CVE-2009-3028?
CVE-2009-3028 allows attackers to force the download of arbitrary files to a user's machine.
Is CVE-2009-3028 being actively exploited?
While it may not be actively exploited at all times, CVE-2009-3028 remains a significant risk if systems are not updated.