Description: | | A remote program execution vulnerability exists in Symantec Altiris Deployment Solution. The vulnerability is due to a flaw in the Altiris eXpress NS SC Download ActiveX control (AeXNSPkgDLLib.dll). The affected control contains certain unsafe methods that can allow arbitrary program execution on a target system. A remote attacker can exploit this vulnerability to download and execute arbitrary programs to a vulnerable system by enticing a user to visit a crafted web page. In a successful attack, where arbitrary code is downloaded and executed on the vulnerable target host, the behaviour of the target system is dependent on the malicious code. |