Altiris Deployment Solution < 6.9.176 Multiple Vulnerabilities

critical Nessus Plugin ID 32323

Synopsis

The remote Windows host has a program that is affected by multiple vulnerabilities.

Description

The version of the Altiris Deployment Solution installed on the remote host reportedly is affected by several issues :

- A SQL injection vulnerability that could allow a user to run arbitrary code (CVE-2008-2286).

- A remote attacker may be able to obtain encrypted Altiris Deployment Solution domain credentials without authentication (CVE-2008-2291).

- A local user could leverage a GUI tooltip to access a privileged command prompt (CVE-2008-2289).

- A local user can modify or delete several registry keys used by the application, resulting in unauthorized access to system information or disruption of service (CVE-2008-2288).

- A local user with access to the install directory of Deployment Solution could replace application components, which might then run with administrative privileges on an affected system (CVE-2008-2287).

Solution

Upgrade to Altiris Deployment Solution 6.9.176 or later and update Agents.

See Also

https://seclists.org/bugtraq/2008/May/196

https://seclists.org/bugtraq/2008/May/198

https://www.zerodayinitiative.com/advisories/ZDI-08-024/

https://www.zerodayinitiative.com/advisories/ZDI-08-025/

https://seclists.org/bugtraq/2008/May/176

https://seclists.org/bugtraq/2008/May/177

http://www.symantec.com/avcenter/security/Content/2008.05.14a.html

Plugin Details

Severity: Critical

ID: 32323

File Name: altiris_deployment_server_6_9_176.nasl

Version: 1.24

Type: remote

Agent: windows

Family: Windows

Published: 5/15/2008

Updated: 11/15/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.0

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Exploitable With

Metasploit (Symantec Altiris DS SQL Injection)

Reference Information

CVE: CVE-2008-2286, CVE-2008-2287, CVE-2008-2288, CVE-2008-2289, CVE-2008-2291

BID: 29196, 29197, 29198, 29199, 29218

CWE: 255, 264, 89

Secunia: 30261