CVE Database
/

CVE-2010-0111

Back to search

CVE-2010-0111

Published: Jan 31, 2011

Modified: Aug 7, 2024

PUBLISHED

Description

HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote attackers to execute arbitrary programs by sending msgsys.exe a UNC share pathname, which is used directly in a CreateProcessA (aka CreateProcess) call.

VendorProductVersions

n/a

n/a

affected
n/a

References

43099
third-party-advisory
x_refsource_SECUNIA
symantec-intelams2-dos(64943)
vdb-entry
x_refsource_XF
43106
third-party-advisory
x_refsource_SECUNIA
45935
vdb-entry
x_refsource_BID
ADV-2011-0234
vdb-entry
x_refsource_VUPEN
1024997
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now