Multiple Symantec Altiris Products 'RunCmd()' ActiveX Control Buffer Overflow Vulnerability
BID:37092
Info
Multiple Symantec Altiris Products 'RunCmd()' ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 37092 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3033 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2009 12:00AM |
| Updated: | Dec 14 2009 06:34PM |
| Credit: | Sebastien Renaud of VUPEN Vulnerability Research Team |
| Vulnerable: |
Symantec Management Platform 7.0 SP1 Symantec Management Platform 7.0 Symantec Altiris Notification Server 6.0 SP3 R7 Symantec Altiris Notification Server 6.0 SP3 Symantec Altiris Notification Server 6.0 SP2 Symantec Altiris Notification Server 6.0 SP1 Symantec Altiris Notification Server 6.0 Symantec Altiris Deployment Solution 6.9.355 SP1 Symantec Altiris Deployment Solution 6.9.355 Symantec Altiris Deployment Solution 6.9.176 Symantec Altiris Deployment Solution 6.9.164 Symantec Altiris Deployment Solution 6.9 SP3 Build 430 Symantec Altiris Deployment Solution 6.9 SP2 build 375 Symantec Altiris Deployment Solution 6.9 SP1 Symantec Altiris Deployment Solution 6.9 |
| Not Vulnerable: | |
Discussion
Multiple Symantec Altiris Products 'RunCmd()' ActiveX Control Buffer Overflow Vulnerability
Symantec Altiris Notification Server, Symantec Management Platform, and Altiris Deployment Solution are prone to a buffer-overflow vulnerability because the applications' web console uses an ActiveX control provided by 'AeXNSConsoleUtilities.dll' that fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Symantec Altiris Notification Server, Symantec Management Platform, and Altiris Deployment Solution are prone to a buffer-overflow vulnerability because the applications' web console uses an ActiveX control provided by 'AeXNSConsoleUtilities.dll' that fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
Multiple Symantec Altiris Products 'RunCmd()' ActiveX Control Buffer Overflow Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A Metasploit exploit module is available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A Metasploit exploit module is available:
Solution / Fix
Multiple Symantec Altiris Products 'RunCmd()' ActiveX Control Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Symantec Altiris Notification Server 6.0 SP3 R7
Symantec Altiris Notification Server 6.0
Symantec Management Platform 7.0
Symantec Altiris Deployment Solution 6.9 SP2 build 375
Symantec Altiris Deployment Solution 6.9 SP1
Symantec Altiris Notification Server 6.0 SP1
Symantec Management Platform 7.0 SP1
Symantec Altiris Notification Server 6.0 SP2
Symantec Altiris Deployment Solution 6.9
Symantec Altiris Notification Server 6.0 SP3
Symantec Altiris Deployment Solution 6.9 SP3 Build 430
Symantec Altiris Deployment Solution 6.9.164
Symantec Altiris Deployment Solution 6.9.176
Symantec Altiris Deployment Solution 6.9.355
Symantec Altiris Deployment Solution 6.9.355 SP1
Solution:
Updates are available. Please see the references for details.
Symantec Altiris Notification Server 6.0 SP3 R7
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6491&aid=50072 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6492&aid=50072
Symantec Altiris Notification Server 6.0
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6491&aid=50072 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6492&aid=50072
Symantec Management Platform 7.0
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6491&aid=50072 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6492&aid=50072
Symantec Altiris Deployment Solution 6.9 SP2 build 375
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6539&aid=50279 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6540&aid=50279
Symantec Altiris Deployment Solution 6.9 SP1
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6539&aid=50279 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6540&aid=50279
Symantec Altiris Notification Server 6.0 SP1
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6491&aid=50072 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6492&aid=50072
Symantec Management Platform 7.0 SP1
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6491&aid=50072 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6492&aid=50072
Symantec Altiris Notification Server 6.0 SP2
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6491&aid=50072 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6492&aid=50072
Symantec Altiris Deployment Solution 6.9
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6539&aid=50279 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6540&aid=50279
Symantec Altiris Notification Server 6.0 SP3
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6491&aid=50072 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6492&aid=50072
Symantec Altiris Deployment Solution 6.9 SP3 Build 430
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6539&aid=50279 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6540&aid=50279
Symantec Altiris Deployment Solution 6.9.164
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6539&aid=50279 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6540&aid=50279
Symantec Altiris Deployment Solution 6.9.176
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6539&aid=50279 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6540&aid=50279
Symantec Altiris Deployment Solution 6.9.355
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6539&aid=50279 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6540&aid=50279
Symantec Altiris Deployment Solution 6.9.355 SP1
-
Symantec AltirisNSConsole.cab
https://kb.altiris.com/utility/getfile.asp?rid=6539&aid=50279 -
Symantec UpdateHeader.cs
https://kb.altiris.com/utility/getfile.asp?rid=6540&aid=50279
References
Multiple Symantec Altiris Products 'RunCmd()' ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Symantec Homepage (Symantec)
- SYM09-016 Security Advisories Relating to Symantec Products - Symantec�??s Altiris (Symantec)
- Vulnerability in the Altiris eXpress NS Console Utilities ActiveX control (Symantec)
- Vulnerability in the Altiris eXpress NS Console Utilities ActiveX control (Symantec)