Security Advisory

CVE-2009-3108

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-09-08 23:00:00
Last updated 2024-08-07 06:14:55
Assigner mitre
State PUBLISHED

Description

The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyone:Full Control), which allows local users to gain privileges by replacing the executable with a Trojan horse program.