CVE-2010-0111
Summary
| CVE | CVE-2010-0111 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-31 21:00:00 UTC |
| Updated | 2017-08-17 01:31:00 UTC |
| Description | HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote attackers to execute arbitrary programs by sending msgsys.exe a UNC share pathname, which is used directly in a CreateProcessA (aka CreateProcess) call. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Antivirus | 10.0 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0 | mr1 | corporate | All |
| Application | Symantec | Antivirus | 10.0 | mr2 | corporate | All |
| Application | Symantec | Antivirus | 10.0.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.1.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.1.2 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.2 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.2.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.2.2 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.3 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.4 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.5 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.6 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.7 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.8 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.9 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1 | mp1 | corporate | All |
| Application | Symantec | Antivirus | 10.1 | mr4 | corporate | All |
| Application | Symantec | Antivirus | 10.1 | mr5 | corporate | All |
| Application | Symantec | Antivirus | 10.1 | mr6 | corporate | All |
| Application | Symantec | Antivirus | 10.1 | mr7 | corporate | All |
| Application | Symantec | Antivirus | 10.1.0.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.4 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.4.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.5 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.5.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.6 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.6.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.7 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.8 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.9 | All | corporate | All |
| Application | Symantec | Antivirus | 10.2 | All | corporate | All |
| Application | Symantec | Antivirus | 10.2 | mr2 | corporate | All |
| Application | Symantec | Antivirus | 10.2 | mr3 | corporate | All |
| Application | Symantec | Antivirus | 10.0 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0 | mr1 | corporate | All |
| Application | Symantec | Antivirus | 10.0 | mr2 | corporate | All |
| Application | Symantec | Antivirus | 10.0.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.1.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.1.2 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.2 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.2.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.2.2 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.3 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.4 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.5 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.6 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.7 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.8 | All | corporate | All |
| Application | Symantec | Antivirus | 10.0.9 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1 | mp1 | corporate | All |
| Application | Symantec | Antivirus | 10.1 | mr4 | corporate | All |
| Application | Symantec | Antivirus | 10.1 | mr5 | corporate | All |
| Application | Symantec | Antivirus | 10.1 | mr6 | corporate | All |
| Application | Symantec | Antivirus | 10.1 | mr7 | corporate | All |
| Application | Symantec | Antivirus | 10.1.0.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.4 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.4.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.5 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.5.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.6 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.6.1 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.7 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.8 | All | corporate | All |
| Application | Symantec | Antivirus | 10.1.9 | All | corporate | All |
| Application | Symantec | Antivirus | 10.2 | All | corporate | All |
| Application | Symantec | Antivirus | 10.2 | mr2 | corporate | All |
| Application | Symantec | Antivirus | 10.2 | mr3 | corporate | All |
| Application | Symantec | Antivirus Central Quarantine Server | 3.5 | All | All | All |
| Application | Symantec | Antivirus Central Quarantine Server | 3.6 | All | All | All |
| Application | Symantec | Antivirus Central Quarantine Server | 3.5 | All | All | All |
| Application | Symantec | Antivirus Central Quarantine Server | 3.6 | All | All | All |
| Application | Symantec | System Center | 10.0 | All | All | All |
| Application | Symantec | System Center | 10.1 | All | All | All |
| Application | Symantec | System Center | 10.0 | All | All | All |
| Application | Symantec | System Center | 10.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| 45935 | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Symantec Antivirus Corporate Edition Intel AMS Service Lets Remote Users Deny Service and Execute Programs - SecurityTracker | SECTRACK | securitytracker.com | |
| Symantec Products Intel Alert Management System Multiple Vulnerabilities - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Symantec Quarantine Server Intel Alert Management System Multiple Vulnerabilities - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| Security Advisories Relating to Symantec Products - Multiple Symantec Intel Alert Management System Arbitrary Message Creation or Denial of Service - 2011-01-26T10:06:16 PST | Symantec | CONFIRM | www.symantec.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.