Altiris Deployment Solution Agent < 6.9.176 Multiple Local Vulnerabilities

high Nessus Plugin ID 32322

Synopsis

The remote Windows host has a program that is affected by multiple vulnerabilities.

Description

The version of the Altiris Deployment Solution Agent installed on the remote host reportedly is affected by several issues :

- A local user could access a privileged command prompt via the Agent's user interface (CVE-2008-2290).

- A local user could leverage a GUI tooltip to access a privileged command prompt (CVE-2008-2289).

- A local user can modify or delete several registry keys used by the application, resulting in unauthorized access to system information or disruption of service (CVE-2008-2288).

- A local user with access to the install directory of Deployment Solution could replace application components, which might then run with administrative privileges on an affected system (CVE-2008-2287).

Solution

Upgrade to Altiris Deployment Solution 6.9.176 or later and update Agents.

See Also

http://www.symantec.com/avcenter/security/Content/2008.05.14a.html

Plugin Details

Severity: High

ID: 32322

File Name: altiris_aclient_6_9_176.nasl

Version: 1.16

Type: local

Agent: windows

Family: Windows

Published: 5/15/2008

Updated: 6/27/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Required KB Items: SMB/Registry/Enumerated

Exploit Ease: No known exploits are available

Exploitable With

Metasploit (Symantec Altiris DS SQL Injection)

Reference Information

CVE: CVE-2008-2287, CVE-2008-2288, CVE-2008-2289, CVE-2008-2290

BID: 29194, 29196, 29197, 29218

CWE: 264

Secunia: 30261