CVE-2009-3108: High severity symantec deployment solution vulnerability
The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyone:Full Control), which allows local users to gain privileges by replacing the executable with a Trojan horse program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3108?
CVE-2009-3108 has a high severity due to the risk of local privilege escalation.
How do I fix CVE-2009-3108?
To fix CVE-2009-3108, update to Symantec Altiris Deployment Solution version 6.9 SP3 Build 430 or later.
What are the affected versions in CVE-2009-3108?
The affected versions of Symantec Altiris Deployment Solution include 6.9, 6.9 SP1, 6.9.164, 6.9.176, and 6.9.355.
What type of attack can exploit CVE-2009-3108?
CVE-2009-3108 can be exploited by local users replacing the vulnerable client executable with a malicious program.
Is there a workaround for CVE-2009-3108?
A possible workaround for CVE-2009-3108 is to change the permissions of the Aclient GUI executable to limit access.