CVE-2009-1431 : Detail

CVE-2009-1431

93.8%V3
Network
2009-04-29
13h00 +00:00
2017-08-16
12h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

XFR.EXE in the Intel File Transfer service in the console in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allows remote attackers to execute arbitrary code by placing the code on a (1) share or (2) WebDAV server, and then sending the UNC share pathname to this service.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 9.3 AV:N/AC:M/Au:N/C:C/I:C/A:C [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Symantec>>Antivirus >> Version To (including) 9.0

Symantec>>Antivirus >> Version From (including) 10 To (including) 10.2

Symantec>>Antivirus >> Version -

Symantec>>Antivirus_central_quarantine_server >> Version *

Symantec>>Client_security >> Version To (including) 2.0

Symantec>>Client_security >> Version From (including) 3.0 To (including) 3.1

Symantec>>Endpoint_protection >> Version To (including) 11.0

Symantec>>System_center >> Version *

References

http://www.vupen.com/english/advisories/2009/1204
Tags : vdb-entry, x_refsource_VUPEN
http://www.securitytracker.com/id?1022132
Tags : vdb-entry, x_refsource_SECTRACK
http://www.securitytracker.com/id?1022130
Tags : vdb-entry, x_refsource_SECTRACK
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=786
Tags : third-party-advisory, x_refsource_IDEFENSE
http://secunia.com/advisories/34856
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.securitytracker.com/id?1022131
Tags : vdb-entry, x_refsource_SECTRACK
http://www.securityfocus.com/bid/34675
Tags : vdb-entry, x_refsource_BID