VulnerabilityModified
CVE-2008-2288
Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 has insufficient access control for deletion and modification of registry keys, which allows local users to cause a denial of service or obtain sensitive information.
LOW 3.6EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 has insufficient access control for deletion and modification of registry keys, which allows local users to cause a denial of service or obtain sensitive information.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- symantec/altiris deployment solution
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=122167472229965&w=2
- http://secunia.com/advisories/30261
- http://www.securityfocus.com/bid/29196
- http://www.securitytracker.com/id?1020024
- http://www.symantec.com/avcenter/security/Content/2008.05.14a.htmlPatch
- http://www.vupen.com/english/advisories/2008/1542/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42441
- http://marc.info/?l=bugtraq&m=122167472229965&w=2
- http://secunia.com/advisories/30261
- http://www.securityfocus.com/bid/29196
- http://www.securitytracker.com/id?1020024
- http://www.symantec.com/avcenter/security/Content/2008.05.14a.htmlPatch
- http://www.vupen.com/english/advisories/2008/1542/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42441
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.