|
|
|
|
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1429
The original article can be found at: http://www.securityfocus.com/bid/34671
|
| |
Vulnerable Systems:
* Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7,
* Symantec AntiVirus (SAV) Corporate Edition 10.0
* Symantec AntiVirus (SAV) Corporate Edition 10.1 before 10.1 MR8,
* Symantec AntiVirus (SAV) Corporate Edition 10.2 before 10.2 MR2;
* Symantec Client Security (SCS) 2 before 2.0 MR7
* Symantec Client Security (SCS)3 before 3.1 MR8;
* Symantec Endpoint Protection (SEP) before 11.0 MR3
The AMS2 (Alert Management Systems 2) component of multiple Symantec products is prone to a remote command-execution vulnerability because the software fails to adequately sanitize user-supplied input.
Successfully exploiting this issue will allow an attacker to execute arbitrary commands with SYSTEM-level privileges, completely compromising affected computers. Failed exploit attempts will result in a denial-of-service condition.
Vendor Status:
Symantec as issued an update for this vulnerablity
Patch Availability:
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_02
CVE Information:
CVE-2009-1429
|
|
|
|
|