CVE-2009-1429
Symantec System Center (SSS)、Symantec AntiVirus Server、Symantec AntiVirus Central Quarantine Server、Symantec AntiVirus (SAV) Corporate Edition 9(9.0 MR7...
- 公開済み
- 2009/04/29
- 更新済み
- 2024/08/07
- CNA の割り当て
- mitre
- 観察された証拠
- 2009/04/28
プライマリ CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C高 · 今後 30 日間
- パーセンタイル
- 99.8%
- モデルの日付
- 2026/09/21
EPSS は統計的な推定値であり、確実性や影響の尺度ではありません。 CVSS、KEV ステータス、暴露、環境と組み合わせます。
概要
Symantec System Center (SSS)、Symantec AntiVirus Server、Symantec AntiVirus Central Quarantine Server、Symantec AntiVirus (SAV) Corporate Edition 9(9.0 MR7 より前)、10.0 および 10.1(10.1 MR8 より前)、10.2(10.2 MR2 より前)、Symantec Client Security (SCS) 2(2.0 MR7 より前)および 3(3.1 MR8 より前)、Symantec Endpoint Protection (SEP)(11.0 MR3 より前)で使用されている Symantec Alert Management System 2 (AMS2) 内の Intel LANDesk Common Base Agent (CBA) には、CreateProcessA 関数によって新しいプロセスで起動されるコマンドとして内容が解釈される細工されたパケットを介して、リモートの攻撃者が任意のコマンドを実行できる脆弱性があります。
ソース
2kingcope · windows · 2009/04/28
- Symantec System Center Alert Management System - 'xfr.exe' Arbitrary Command Execution (Metasploit)エクスプロイト
Metasploit · windows · 2011/08/19
責任ある使用
脆弱性情報は、自分が所有しているシステム、またはテストを許可されているシステムでのみ使用してください。 Kitploit は公開研究メタデータにリンクしており、エクスプロイト コードや悪意のあるペイロードは保存しません。