Vulnerability Description
The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack on the "command prompt" hidden GUI button to (1) overwrite the CommandLine parameter to cmd.exe to use SYSTEM privileges and (2) modify the DLL that is loaded using the LoadLibrary API function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Altiris Deployment Solution | >= 6.0, < 6.9.355 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=122460544316205&w=2Mailing List
- http://osvdb.org/49426Broken Link
- http://secunia.com/advisories/31773Broken LinkVendor Advisory
- http://www.insomniasec.com/advisories/ISVA-081020.1.htmBroken LinkPatch
- http://www.securityfocus.com/bid/31766Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1021071Broken LinkThird Party AdvisoryVDB Entry
- http://www.symantec.com/avcenter/security/Content/2008.10.20a.htmlBroken LinkPatchVendor Advisory
- http://www.vupen.com/english/advisories/2008/2876Broken LinkPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46006Third Party AdvisoryVDB Entry
- http://marc.info/?l=bugtraq&m=122460544316205&w=2Mailing List
- http://osvdb.org/49426Broken Link
- http://secunia.com/advisories/31773Broken LinkVendor Advisory
- http://www.insomniasec.com/advisories/ISVA-081020.1.htmBroken LinkPatch
- http://www.securityfocus.com/bid/31766Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1021071Broken LinkThird Party AdvisoryVDB Entry
FAQ
What is CVE-2008-6827?
CVE-2008-6827 is a vulnerability with a CVSS score of 7.8 (HIGH). The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "S...
How severe is CVE-2008-6827?
CVE-2008-6827 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-6827?
Check the references section above for vendor advisories and patch information. Affected products include: Symantec Altiris Deployment Solution.