Vulnerabilities > CVE-2007-5838 - Configuration vulnerability in Symantec Altiris Deployment Solution 6/6.8

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
symantec
CWE-16
nessus

Summary

Aclient in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows local users to gain local System privileges via the "Enable key-based authentication to Deployment server" browser option, a different issue than CVE-2007-4380.

Vulnerable Configurations

Part Description Count
Application
Symantec
4

Common Weakness Enumeration (CWE)

Nessus

NASL familyWindows
NASL idALTIRIS_6_8_380.NASL
descriptionThe version of the Altiris Client Agent (aclient) installed on the remote host contains a flaw in its browser option whereby a local user can open or execute files on the affected host with SYSTEM privileges. It also contains a directory traversal vulnerability that allows a local user to read privileged system files.
last seen2020-06-01
modified2020-06-02
plugin id27596
published2007-10-31
reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/27596
titleAltiris AClient < 6.8.380 Local Vulnerabilities