← Vulnerability feed

Vulnerability record · CVE-2008-6827 · published 8 June 2009

CVE-2008-6827: Symantec altiris deployment solution missing authentication for critical function vulnerability

Symantec · Altiris Deployment Solution

The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack on the "command prompt" hidden GUI button to (1) overwrite the CommandLine parameter to cmd.exe to use SYSTEM privileges and (2) modify the DLL that is loaded using the LoadLibrary API function.

7.8 CVSS 3.1 High EPSS 1.1% · top 36.1% CWE-306 · Missing authentication for critical function
7.8CVSS 3.1 base score, v2 6.8
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack on the "command prompt" hidden GUI button to (1) overwrite the CommandLine parameter to cmd.exe to use SYSTEM privileges and (2) modify the DLL that is loaded using the LoadLibrary API function.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-6827 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-3179Symantec altiris deployment solution vulnerabilityMultiple unspecified vulnerabilities in Symantec Altiris Deployment Solution 6.9 might allow remote attackers to execute arbitrary code via unknown c…EPSS 5.3%9.3CVE-2009-3033Symantec altiris deployment solution memory buffer overflow vulnerabilityBuffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in S…EPSS 40%9.3CVE-2009-3031Symantec Altiris ConsoleUtilities ActiveX stack buffer overflowThe BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control (AeXNSConsoleUtilities.dll) contains a stack-based buffer ove…EPSS 45%analysed9.3CVE-2009-3109Symantec altiris deployment solution vulnerabilityUnspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication …EPSS 3.8%9.3CVE-2008-4564Autonomy keyview export sdk memory buffer overflow vulnerabilityStack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) produ…EPSS 6.8%7.8CVE-2009-3178Symantec altiris deployment solution vulnerabilityUnspecified vulnerability in mm.exe in Symantec Altiris Deployment Solution 6.9 allows remote attackers to cause a denial of service via unknown atta…EPSS 2.6%7.8CVE-2008-6828Symantec altiris deployment solution cleartext storage of sensitive data vulnerabilitySymantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows loc…EPSS 0.25%7.5CVE-2008-2286Symantec altiris deployment solution sql injection vulnerabilitySQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute…EPSS 33%

Source: NIST National Vulnerability Database (record CVE-2008-6827), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.