CVE-2025-9059: Elevation of Privileges Vulnerability in IT Management Suite
Published Sep 11, 2025
·Updated
The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.
Affected Software
1 affected component
Symantec Altiris Core Agent
Event History
Sep 11, 2025
CVE Published
via MITRE·05:18 AM
Data Sourced
via MITRE·05:18 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Feb 28, 57989
Event
via FIRST·04:03 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9059?
CVE-2025-9059 has a high severity due to the potential for elevation of privileges through DLL hijacking.
2
How do I fix CVE-2025-9059?
To fix CVE-2025-9059, ensure that you update the Altiris Core Agent to the latest version released by Symantec.
3
What is the impact of CVE-2025-9059?
The impact of CVE-2025-9059 allows an attacker to execute arbitrary code with elevated privileges on the affected system.
4
Which software is affected by CVE-2025-9059?
CVE-2025-9059 affects the Symantec Altiris Core Agent software package.
5
How does CVE-2025-9059 exploit DLL hijacking?
CVE-2025-9059 exploits DLL hijacking by loading a malicious DLL instead of a legitimate one during the update process of the Altiris Core Agent.