Symantec System Center Alert Management System (xfr.exe) Arbitrary Command Execution

Strike ID:
E09-43p01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2009

Description

Symantec System Center Alert Management System is prone to a remote command-injection vulnerability because the application fails to properly sanitize user-supplied input, specifically with regards to the CreateProcessA function. This strike delivers an attack which is consistent with exploiting this vulnerability and achieves arbitrary command execution.

CVE

References

Bid