« Volver al listado

CVE-2009-1429

Estado: ModificadaAlta (10)—💥 Exploit

The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allows remote attackers to execute arbitrary commands via a crafted packet whose contents are interpreted as a command to be launched in a new process by the CreateProcessA function.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-1429",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-04-29T15:30:00.217",
  "references": [
    {
      "url": "http://osvdb.org/54157",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/34856",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/8346",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/34671",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1022130",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1022131",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1022132",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_02",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1204",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50176",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/54157",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34856",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/8346",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/34671",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1022130",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1022131",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1022132",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_02",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1204",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50176",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allows remote attackers to execute arbitrary commands via a crafted packet whose contents are interpreted as a command to be launched in a new process by the CreateProcessA function."
    },
    {
      "lang": "es",
      "value": "El LANDesk Common Base Agent (CBA) de Intel en Alert Management System 2 (AMS2) de Symantec, tal y como es usado en System Center (SSS) de Symantec; AntiVirus Server de Symantec; AntiVirus Central Quarantine Server de Symantec; Symantec AntiVirus (SAV) Corporate Edition versiones 9 anteriores a 9.0 MR7, versiones 10.0 y 10.1 anteriores a 10.1 MR8, y versiones 10.2 anteriores a 10.2 MR2; Symantec Client Security (SCS) versiones 2 anteriores a 2.0 MR7 y versiones 3 anteriores a 3.1 MR8; y Symantec Endpoint Protection (SEP) anterior a versión 11.0 MR3, permite a atacantes remotos ejecutar comandos arbitrarios por medio de un paquete diseñado cuyo contenido se interpreta como un comando para ser iniciado en un nuevo proceso mediante la función CreateProcessA."
    }
  ],
  "lastModified": "2026-06-16T23:07:15.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:*:-:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "658366BE-0214-4388-9C96-ABEB9E60C213",
              "versionEndIncluding": "9.0"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:*:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4CD3B130-38CD-4B85-B054-EE43C205E935",
              "versionEndIncluding": "10.1"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:*:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C754F33C-88E5-45A7-96D9-91C0D0397ED8",
              "versionEndIncluding": "10.2"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:-:-:srv:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91397AE1-03FB-4938-8E4F-6E0A29DD1D61"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEB639EF-B434-42ED-A162-A2593FA78E3E"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.1:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BA427D2-2F74-4314-B68A-164E2B6B0240"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.1.1:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "549049F7-2698-4F68-A1D0-1E4546B9EB23"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.2:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E86D9CE-8A86-498B-B3A3-8988274A91E5"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.2.1:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBF13A92-83EF-44EE-AD87-BA0CF8FF266D"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.2.2:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D92B456D-A69E-4B10-8F74-D3DFC242F641"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.3:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "643AF180-138C-472A-8BC5-B8B028E77CDD"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.4:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D56068D-CEF2-46B7-9914-36AB961839C9"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.5:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8ADDF27-67FF-41D7-BF2E-87AE06FDECD7"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.6:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "002290DD-589E-404F-BFC0-A1239D0E92E3"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.7:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2854BCF-2D37-4BE9-A590-7E25DF443EFF"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.8:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BDB19A7-8DFA-43AD-9C44-16BBCF4531B7"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus:10.0.9:*:corporate:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED683B68-530A-436F-A49B-32890EDFAC93"
            },
            {
              "criteria": "cpe:2.3:a:symantec:antivirus_central_quarantine_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8ABFB83-2B3D-4F73-A849-1910D8BCA622"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64CC7EDE-5A85-4D8E-99B0-FF6690BCE35E",
              "versionEndIncluding": "3.1"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DDD0E02-306D-4675-B73A-2C2F619CDDCF"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "844A6963-F60C-4D48-8445-9056C99201D6"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.0.359:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDB1C90D-DBC0-4DA0-AF5D-E42C41E84B60"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.1.1000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2852548A-39A6-44FB-A73E-96507BA0CD8C"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.1.1001:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB9641FC-FF7B-4413-8163-B795AA35C888"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.1.1007:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17862D7F-7001-46B8-A415-2A15A247E9BD"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.1.1008:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "170AEE7B-31AF-44E2-9B63-9703D0DE721C"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.1.1009:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E651C9BE-201B-4DDC-A650-F9269531290C"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56EA0BAC-ED6D-45D2-995C-18B828906E1C"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.2.2000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63B1A9FC-707C-4F6F-959B-30B28E43D202"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.2.2001:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87E4E013-A819-42E0-8F8E-9B2D409F900E"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.2.2002:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "097B87A8-8176-4426-BDE4-6FDDD272E1B9"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.2.2010:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5EBD7767-C352-435B-8963-83F723FFD302"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.2.2011:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2FC1708-B643-4489-A59C-EBDAFD9B0078"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.2.2020:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DCE0C8A-A97C-4DE1-B0EE-3A2D16A34C77"
            },
            {
              "criteria": "cpe:2.3:a:symantec:client_security:3.0.2.2021:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE714705-CEE9-4BA1-8573-FD3765BC7F94"
            },
            {
              "criteria": "cpe:2.3:a:symantec:endpoint_protection:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C77B51F3-AB82-4C0A-8341-73CC9650F841",
              "versionEndIncluding": "11.0"
            },
            {
              "criteria": "cpe:2.3:a:symantec:system_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FEBAB5D5-E3B7-4D65-80E8-C0E5B40A95A8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}