NONE · 0

CVE-2026-15379

The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admi...

Vulnerability Description

The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller. Any local standard user can therefore read SYSTEM-readable files — including configuration files, service logs, and secrets stored with SYSTEM/Administrator-only ACLs — by querying the provider directly.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-15379?

CVE-2026-15379 is a documented vulnerability. The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admi...

How severe is CVE-2026-15379?

CVSS scoring is not yet available for CVE-2026-15379. Check NVD for updates.

Is there a patch for CVE-2026-15379?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.