Vulnerability record · CVE-2009-1429 · published 29 April 2009
CVE-2009-1429: Symantec AMS2 Intel LANDesk CBA Remote Command Execution
Symantec · Antivirus
The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2) passes crafted packet contents directly to the CreateProcessA function, allowing code injection. This affects multiple Symantec products including System Center, AntiVirus Corporate Edition, Client Security, and Endpoint Protection. A remote, unauthenticated attacker can execute arbitrary commands on the affected host.
Description
The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allows remote attackers to execute arbitrary commands via a crafted packet whose contents are interpreted as a command to be launched in a new process by the CreateProcessA function.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0, remote unauthenticated code execution, high EPSS, and public exploit code make this an urgent risk for any unpatched system.
What it is
The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2) passes crafted packet contents directly to the CreateProcessA function, allowing code injection. This affects multiple Symantec products including System Center, AntiVirus Corporate Edition, Client Security, and Endpoint Protection. A remote, unauthenticated attacker can execute arbitrary commands on the affected host.
Impact
An attacker gains remote code execution with the privileges of the vulnerable service, which typically runs as SYSTEM. This can lead to full compromise of the host and any managed endpoints.
Attack surface
The flaw is reachable over the network via a crafted packet sent to the AMS2/CBA service, as indicated by the CVSS vector AV:N/AC:L/Au:N. No authentication or user interaction is required.
Exploitation
The record is not listed in CISA KEV, but EPSS is very high (0.877, 99.75th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.
What to do
- Apply the vendor patches referenced in Symantec advisory 20090428_02 (e.g., SAV 9.0 MR7, 10.1 MR8, 10.2 MR2, SCS 2.0 MR7, 3.1 MR8, SEP 11.0 MR3).
- If patching is not immediately possible, restrict network access to the AMS2/CBA service ports to trusted management hosts only.
- Segment or isolate systems running affected Symantec products until they can be upgraded.
- Monitor for unexpected child processes spawned by the Symantec AMS2/CBA service.
Detection
- Hunt for processes created by the Symantec AMS2/CBA service (e.g., via Sysmon Event ID 1) that are not part of normal operations.
- Monitor network traffic to AMS2/CBA ports for anomalous packets or connections from untrusted sources.
- Review host logs for command-line arguments or process creations matching known exploit patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-1429 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-1429), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.