← All CVEs

CVE-2009-3028

medium · 6.8

The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.

6.8
CVSS
42.6%
EPSS (exploit prob.)
99th
EPSS percentile
2011-03-07
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
symantecaltiris_deployment_solution6.9
symantecaltiris_deployment_solution6.9
symantecaltiris_deployment_solution6.9
symantecaltiris_deployment_solution6.9
symantecaltiris_deployment_solution6.9
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecaltiris_notification_server6.0
symantecmanagement_platform7.0
symantecmanagement_platform7.0
symantecmanagement_platform7.0
symantecmanagement_platform7.0
symantecmanagement_platform7.0
symantecmanagement_platform7.0
symantecmanagement_platform7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-3028