Update Protection against Symantec Alert Management System Intel File Transfer Service Arbitrary Program Execution Vulnerability
| Check Point Reference: | CPAI-2009-087 | |
| Date Published: | ||
| Preemptive Since: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Secunia Advisory: SA34856 |
|
| Industry Reference(s): | ||
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Symantec Client Security 2.0.x prior to 2.0 MR7 Symantec Client Security 3.x prior to 3.1 MR8 Symantec AntiVirus Corporate Edition 9.0.x prior to 9.0 MR7 Symantec AntiVirus Corporate Edition 10.x prior to 10.1 MR8 Symantec Endpoint Protection 11.x prior to 11.0 MR3 | ||
| Vulnerability Description A design error was reported in Symantec Alert Management System Console component shipped with Symantec software. The vulnerability is due to a design error in the Intel File Transfer service (XFR.EXE), a service used to aid communication between the core server and managed clients. The vulnerability can be exploited by remote unauthenticated attackers to execute arbitrary code on the target host. |
||
|
Vulnerability Details Symantec System Center provides centralized systems and policy management for Norton Antivirus Enterprise Solution across multiple Windows NT and NetWare networks. The vulnerability is due to a design error in XFR.EXE while transferring files to AMS2. Successful exploitation could result in remote code execution. |
Protection Overview
This protection will detect and block unauthenticated commands to the Intel File Transfer service.
In order for the protection to be activated, update your Security Gateway/VPN-1/InterSpect product to the latest IPS/SmartDefense update. For information on how to update IPS/SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
Symantec Alert Management System 2 multiple vulnerabilities