The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyone:Full Control), which allows local users to gain privileges by replacing the executable with a Trojan horse program.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Altiris_deployment_solution | Symantec | 6.9 (including) | 6.9 (including) |
Altiris_deployment_solution | Symantec | 6.9-sp1 (including) | 6.9-sp1 (including) |
Altiris_deployment_solution | Symantec | 6.9.164 (including) | 6.9.164 (including) |
Altiris_deployment_solution | Symantec | 6.9.176 (including) | 6.9.176 (including) |
Altiris_deployment_solution | Symantec | 6.9.355 (including) | 6.9.355 (including) |
Altiris_deployment_solution | Symantec | 6.9.355-sp1 (including) | 6.9.355-sp1 (including) |