Intel Common Base Agent CreateProcessA() Function Remote Command Execution

This script is Copyright (C) 2009-2016 Tenable Network Security, Inc.


Synopsis :

The remote service seems to allow execution of arbitrary commands.

Description :

The remote host seems to be running a version of the Intel LANDesk
Common Base Agent (CBA) that allows the contents of a specially
crafted packet to be passed as an argument to 'CreateProcessA()' to be
executed on the remote host with SYSTEM privileges.

See also :

http://www.nessus.org/u?33c06995

Solution :

If using Symantec AntiVirus Corporate Edition, Symantec Client
Security, or Symantec Endpoint Protection, apply the appropriate
update as described in Symantec's advisory referenced above.

Otherwise, contact the application's vendor for an update.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.3
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 38664 (landesk_cba_createprocessa_cmd_exec.nasl)

Bugtraq ID: 34671

CVE ID: CVE-2009-1429

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now