Intel Common Base Agent CreateProcessA() Function Remote Command Execution
Critical Nessus Plugin ID 38664
SynopsisThe remote service seems to allow execution of arbitrary commands.
DescriptionThe remote host seems to be running a version of the Intel LANDesk Common Base Agent (CBA) that allows the contents of a specially crafted packet to be passed as an argument to 'CreateProcessA()' to be executed on the remote host with SYSTEM privileges.
SolutionIf using Symantec AntiVirus Corporate Edition, Symantec Client Security, or Symantec Endpoint Protection, apply the appropriate update as described in Symantec's advisory referenced above.
Otherwise, contact the application's vendor for an update.