← Vulnerability feed

Vulnerability record · CVE-2008-2794 · published 20 June 2008

CVE-2008-2794: Symantec altiris notification server permissions and access controls vulnerability

Symantec · Altiris Notification Server

Unspecified vulnerability in the GUI in Symantec Altiris Notification Server Agent 6.x before 6.0 SP3 R8 allows local users to gain privileges via unknown attack vectors.

6.8 CVSS 2.0 Medium EPSS 0.31% · top 78.2% CWE-264 · Permissions and access controls
6.8CVSS 2.0 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the GUI in Symantec Altiris Notification Server Agent 6.x before 6.0 SP3 R8 allows local users to gain privileges via unknown attack vectors.

AV:L/AC:L/Au:S/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2794 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-3033Symantec altiris deployment solution memory buffer overflow vulnerabilityBuffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in S…EPSS 40%9.3CVE-2009-3031Symantec Altiris ConsoleUtilities ActiveX stack buffer overflowThe BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control (AeXNSConsoleUtilities.dll) contains a stack-based buffer ove…EPSS 45%analysed6.8CVE-2009-3028Symantec altiris deployment solution vulnerabilityThe Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6…EPSS 43%6.8CVE-2008-0716Symantec altiris notification server vulnerabilityThe agent in Symantec Altiris Notification Server before 6.0 SP3 R7 allows local users to gain privileges via a "Shatter" style attack.EPSS 0.30%4.3CVE-2009-3035Symantec altiris notification server vulnerabilityThe web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and cer…EPSS 0.37%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed7.8CVE-2016-3643SolarWinds Virtualization Manager sudo misconfiguration privilege escalationSolarWinds Virtualization Manager 6.3.1 and earlier ship with a misconfigured sudo policy that lets a local user run privileged commands, as shown by…KEVEPSS 3.7%analysed

Source: NIST National Vulnerability Database (record CVE-2008-2794), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.