Altiris Altiris.AeXNSPkgDL.1 ActiveX Control DownloadAndInstall() Method Arbitrary Code Execution

This script is Copyright (C) 2009-2014 Tenable Network Security, Inc.


Synopsis :

The remote Windows host has an ActiveX control that allows execution
of arbitrary code.

Description :

The Altiris.AeXNSPkgDL.1 ActiveX control, a component of Altiris
Deployment Solution, Altiris Notification Server, and Symantec
Management Platform, is installed on the remote Windows host.

The installed version of this control provides an unsafe method, named
'DownloadAndInstall'.

If an attacker can trick a user on the affected host into viewing a
specially crafted HTML document, this issue could be leveraged to
download and execute arbitrary code on the affected system subject
to the user's privileges.

See also :

http://www.nessus.org/u?81f3a7d5
http://www.nessus.org/u?01cdad31
http://www.symantec.com/business/support/index?page=content&id=TECH44885

Solution :

Either set the kill bit or apply the vendor's hotfix to upgrade the
control to version 6.0.0.2000 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.7
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 41062 (altiris_aexnspkgdllib_activex_download.nasl)

Bugtraq ID: 36346

CVE ID: CVE-2009-3028

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now