Symantec Altiris Deployment Solution TFTP/MTFTP Service Directory Traversal Vulnerability
1 Nov. 2007
Summary
Symantec Altiris Deployment Solution is "an automated OS deployment solution that is used for deploying and managing servers, desktops, and notebooks from a central location". Remote exploitation of a directory traversal vulnerability in Symantec's Altiris Deployment Solution products could allow attackers to gain read access to arbitrary files hosted on the Altiris server.
Vulnerable Systems:
* Altiris Deployment Solution for Windows version 6.8 (pxemtftp.exe version 6.8.8297.48)
Immune Systems:
*
Altiris Deployment Solution includes a tftp/mtftp server within its optional PXE server component which suffers from a directory traversal condition. The server runs with SYSTEM level privileges and allows unauthenticated attackers to download any file on the system.
Analysis:
Exploitation allows attackers to read arbitrary files from the server machine. The tftp/mftp daemon runs with SYSTEM level privileges, so any file readable by SYSTEM with a known file path can be downloaded without authentication.
Workaround:
If the PXE server component is not required in your environment it should be disabled.