Description Preview
The vulnerabilities in the Intel Alert Management System (AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, are due to multiple stack-based buffer overflows. These overflows can be exploited by remote attackers to execute arbitrary code via a long string to msgsys.exe, a long modem string or PIN number to msgsys.exe, or a message to msgsys.exe. These are related to various functions and services within the Intel Alert Handler service and the Intel Alert Originator service.
Overview
The vulnerabilities are due to improper handling of certain inputs by the affected software. An attacker could exploit these vulnerabilities by sending a crafted request to the affected software. An exploit could allow the attacker to execute arbitrary code and gain control of the system.
Remediation
Users of the affected software are advised to update to the latest versions which have the vulnerabilities fixed. Symantec has released updates to address these vulnerabilities. Users should contact Symantec or their vendor for appropriate patches or updates.
References
- http://www.zerodayinitiative.com/advisories/ZDI-11-031
- http://www.zerodayinitiative.com/advisories/ZDI-11-028
- http://secunia.com/advisories/43099
- http://www.zerodayinitiative.com/advisories/ZDI-11-032
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110126_00
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64940
- http://www.zerodayinitiative.com/advisories/ZDI-11-030
- http://secunia.com/advisories/43106
- http://securitytracker.com/id?1024996
- http://www.securityfocus.com/bid/45936
- http://www.vupen.com/english/advisories/2011/0234
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- ConstructionConstruction
- Educational ServicesEducational Services
- Finance and InsuranceFinance and Insurance
- Health Care & Social AssistanceHealth Care & Social Assistance
- InformationInformation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- ManufacturingManufacturing
- MiningMining
- Other Services (except Public Administration)Other Services (except Public Administration)
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Public AdministrationPublic Administration
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Retail TradeRetail Trade
- Transportation & WarehousingTransportation & Warehousing
- UtilitiesUtilities
- Wholesale TradeWholesale Trade