Vulnerabilities > CVE-2009-3109 - Authentication Handshake Race Condition Security vulnerability in Symantec Altiris Deployment Solution 6.9
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Unspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication is being used between a deployment server and a client, allows remote attackers to bypass authentication and execute arbitrary commands as SYSTEM by spoofing the deployment server and sending "alternate commands" before the handshake is completed.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | Windows |
NASL id | ALTIRIS_DEPLOYMENT_SOLUTION_SERVER_6_9_430.NASL |
description | The version of Altiris Deployment Solution installed on the remote host is reportedly affected by the following vulnerabilities : - DBManager authentication can by bypassed. A remote attacker could exploit this to execute arbitrary database queries. (CVE-2009-3107) - The Aclient GUI has a privilege escalation vulnerability. This could allow an unprivileged user to compromise the client. (CVE-2009-3108) - When key-based authentication is being used, it is possible to issue commands to an agent before the handshake is completed. A malicious server could exploit this to execute arbitrary commands as SYSTEM. (CVE-2009-3109) - Due to a race condition, a malicious user could intercept a file transfer meant for a legitimate client. This could result in the disclosure of sensitive information, or a denial of service. (CVE-2009-3110) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 43828 |
published | 2010-01-08 |
reporter | This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/43828 |
title | Altiris Deployment Solution Server < 6.9.430 Multiple Vulnerabilities (SYM09-011) |
code |
|