CVE-2008-2287
Estado: ModificadaAlta (7.2)—
Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 does not properly protect the install directory, which might allow local users to gain privileges by replacing an application component with a Trojan horse.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.35%
- Percentil entre todas las CVEs puntuadas: 26
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://marc.info/?l=bugtraq&m=122167472229965&w=2
- http://secunia.com/advisories/30261
- http://www.securityfocus.com/bid/29197
- http://www.securitytracker.com/id?1020024
- http://www.symantec.com/avcenter/security/Content/2008.05.14a.html
- http://www.vupen.com/english/advisories/2008/1542/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42442
- http://marc.info/?l=bugtraq&m=122167472229965&w=2
- http://secunia.com/advisories/30261
- http://www.securityfocus.com/bid/29197
- http://www.securitytracker.com/id?1020024
- http://www.symantec.com/avcenter/security/Content/2008.05.14a.html
- http://www.vupen.com/english/advisories/2008/1542/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42442
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-2287",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-05-18T14:20:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=122167472229965&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/30261",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/29197",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1020024",
"source": "cve@mitre.org"
},
{
"url": "http://www.symantec.com/avcenter/security/Content/2008.05.14a.html",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/1542/references",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42442",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=122167472229965&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/30261",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/29197",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1020024",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.symantec.com/avcenter/security/Content/2008.05.14a.html",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/1542/references",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42442",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 does not properly protect the install directory, which might allow local users to gain privileges by replacing an application component with a Trojan horse."
},
{
"lang": "es",
"value": "Symantec Altiris Deployment Solution 6.8.x y 6.9.x anterior a 6.9.176 no protege correctamente el directorio install, lo que podría permitir a usuarios locales obtener privilegios reemplazando un componente de una aplicación por un troyano."
}
],
"lastModified": "2026-06-16T22:53:28.387",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:6.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F838B26-BCE1-4663-95B1-B40BAB4F614E"
},
{
"criteria": "cpe:2.3:a:symantec:altiris_deployment_solution:6.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F0002047-0965-4086-A5E6-AEC02200B6CF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}