Home
HIGH: 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:A/V:C/RE:M/U:RedDefault status
unaffected
8.6.x
affected
8.7.x
affected
8.8
affected
Description
The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.
Problem types
CWE-427 Uncontrolled Search Path Element
CWE-269 Improper Privilege Management
Product status
8.6.x
8.7.x
8.8
Credits
Sandro Poppi
References
support.broadcom.com/...l/content/SecurityAdvisories/0/36132