RULE(RULE ID:322547)

Rule General Information
Release Date: 2019-07-06
Rule Name: Symantec Altiris Deployment Solution Arbitrary File Download and Execution Vulnerability (CVE-2009-3028)
Severity:
CVE ID:
Rule Protection Details
Description: The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:36346
http://www.symantec.com/business/support/index?page=content&id=TECH44885
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090922_00
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.symantec.com/business/support/index?page=content&id;=TECH44885