Altiris Deployment Solution Agent < 6.9.176 Multiple Local Vulnerabilities
High Nessus Plugin ID 32322
SynopsisThe remote Windows host has a program that is affected by multiple vulnerabilities.
DescriptionThe version of the Altiris Deployment Solution Agent installed on the remote host reportedly is affected by several issues :
- A local user could access a privileged command prompt via the Agent's user interface (CVE-2008-2290).
- A local user could leverage a GUI tooltip to access a privileged command prompt (CVE-2008-2289).
- A local user can modify or delete several registry keys used by the application, resulting in unauthorized access to system information or disruption of service (CVE-2008-2288).
- A local user with access to the install directory of Deployment Solution could replace application components, which might then run with administrative privileges on an affected system (CVE-2008-2287).
SolutionUpgrade to Altiris Deployment Solution 6.9.176 or later and update Agents.