Altiris Deployment Solution < 6.9.176 Multiple Vulnerabilities

Critical Nessus Plugin ID 32323


The remote Windows host has a program that is affected by multiple vulnerabilities.


The version of the Altiris Deployment Solution installed on the remote host reportedly is affected by several issues :

- A SQL injection vulnerability that could allow a user to run arbitrary code (CVE-2008-2286).

- A remote attacker may be able to obtain encrypted Altiris Deployment Solution domain credentials without authentication (CVE-2008-2291).

- A local user could leverage a GUI tooltip to access a privileged command prompt (CVE-2008-2289).

- A local user can modify or delete several registry keys used by the application, resulting in unauthorized access to system information or disruption of service (CVE-2008-2288).

- A local user with access to the install directory of Deployment Solution could replace application components, which might then run with administrative privileges on an affected system (CVE-2008-2287).


Upgrade to Altiris Deployment Solution 6.9.176 or later and update Agents.

See Also

Plugin Details

Severity: Critical

ID: 32323

File Name: altiris_deployment_server_6_9_176.nasl

Version: $Revision: 1.22 $

Type: remote

Agent: windows

Family: Windows

Published: 2008/05/15

Modified: 2016/11/11

Dependencies: 25897

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 9.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:U/RC:ND

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Exploitable With

Metasploit (Symantec Altiris DS SQL Injection)

Reference Information

CVE: CVE-2008-2286, CVE-2008-2287, CVE-2008-2288, CVE-2008-2289, CVE-2008-2291

BID: 29196, 29197, 29198, 29199, 29218

OSVDB: 45313, 45314, 45315, 45316, 45317, 45318

Secunia: 30261

CWE: 89, 255, 264