The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2011-03-07T20:00:00

Updated: 2013-02-07T10:00:00

Reserved: 2009-08-31T00:00:00


Link: CVE-2009-3028

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2011-03-07T21:00:01.110

Modified: 2013-02-07T04:21:27.547


Link: CVE-2009-3028

JSON object: View

cve-icon Redhat Information

No data.