← Vulnerability feed

Vulnerability record · CVE-2009-1429 · published 29 April 2009

CVE-2009-1429: Symantec AMS2 Intel LANDesk CBA Remote Command Execution

Symantec · Antivirus

The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2) passes crafted packet contents directly to the CreateProcessA function, allowing code injection. This affects multiple Symantec products including System Center, AntiVirus Corporate Edition, Client Security, and Endpoint Protection. A remote, unauthenticated attacker can execute arbitrary commands on the affected host.

10.0 CVSS 2.0 High EPSS 88% · top 0.2% CWE-94 · Code injection
10.0CVSS 2.0 base score
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allows remote attackers to execute arbitrary commands via a crafted packet whose contents are interpreted as a command to be launched in a new process by the CreateProcessA function.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0, remote unauthenticated code execution, high EPSS, and public exploit code make this an urgent risk for any unpatched system.

What it is

The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2) passes crafted packet contents directly to the CreateProcessA function, allowing code injection. This affects multiple Symantec products including System Center, AntiVirus Corporate Edition, Client Security, and Endpoint Protection. A remote, unauthenticated attacker can execute arbitrary commands on the affected host.

Impact

An attacker gains remote code execution with the privileges of the vulnerable service, which typically runs as SYSTEM. This can lead to full compromise of the host and any managed endpoints.

Attack surface

The flaw is reachable over the network via a crafted packet sent to the AMS2/CBA service, as indicated by the CVSS vector AV:N/AC:L/Au:N. No authentication or user interaction is required.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high (0.877, 99.75th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.

What to do

  • Apply the vendor patches referenced in Symantec advisory 20090428_02 (e.g., SAV 9.0 MR7, 10.1 MR8, 10.2 MR2, SCS 2.0 MR7, 3.1 MR8, SEP 11.0 MR3).
  • If patching is not immediately possible, restrict network access to the AMS2/CBA service ports to trusted management hosts only.
  • Segment or isolate systems running affected Symantec products until they can be upgraded.
  • Monitor for unexpected child processes spawned by the Symantec AMS2/CBA service.

Detection

  • Hunt for processes created by the Symantec AMS2/CBA service (e.g., via Sysmon Event ID 1) that are not part of normal operations.
  • Monitor network traffic to AMS2/CBA ports for anomalous packets or connections from untrusted sources.
  • Review host logs for command-line arguments or process creations matching known exploit patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-1429 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0108Symantec antivirus memory buffer overflow vulnerabilityBuffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9…EPSS 19%10.0CVE-2006-2630Symantec Antivirus and Client Security stack buffer overflowSymantec Antivirus 10.1 and Client Security 3.1 contain a stack-based buffer overflow that remote attackers can trigger through unspecified attack ve…EPSS 74%analysed10.0CVE-2004-0444Symantec client firewall vulnerabilityMultiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 throug…EPSS 13%9.8CVE-2016-3645Symantec norton security vulnerabilityInteger overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…EPSS 25%9.3CVE-2012-4953Symantec antivirus memory buffer overflow vulnerabilityThe decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corpor…EPSS 6.0%9.3CVE-2012-0295Symantec endpoint protection code injection vulnerabilityThe Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-…EPSS 4.0%9.3CVE-2011-0688Symantec antivirus improper authentication vulnerabilityIntel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Cente…EPSS 4.0%9.3CVE-2010-0111Symantec antivirus improper input validation vulnerabilityHDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as used in S…EPSS 35%

Source: NIST National Vulnerability Database (record CVE-2009-1429), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.