This application requires Javascript for optimal performance.

Symantec.Alert.Management.System.HNDLRSVC.Command.Execution

Release Date

Sep 28, 2010

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against an arbitrary command-execution vulnerability in the Symantec Alert Management System (AMS2) service, which is shipped with multiple Symantec products.

The vulnerability is caused by an error when the vulnerable service handles a specially crafted packet. It allows a remote attacker to execute arbitrary commands.

Affected Products

Symantec AntiVirus Corporate Edition 10.1.7 .7000 (MR7) and previous versions

Recommended Actions

Currently we are not aware of any patches supplied by the vendor for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2010-0110

Reference/s

http://www.securityfocus.com/bid/41959 (BugTraq)

Reference: VID-24348