← Vulnerability feed

Vulnerability record · CVE-2009-1430 · published 29 April 2009

CVE-2009-1430: Symantec Alert Management System IAO.EXE stack buffer overflow

Symantec · Antivirus

IAO.EXE in the Symantec Alert Originator Service (Alert Management System 2, shipped with System Center, AntiVirus, Client Security and Endpoint Protection) contains multiple stack-based buffer overflows. A remote attacker can trigger them with a crafted packet or with data that appears to come from the MsgSys.exe process, leading to arbitrary code execution on the affected host.

9.3 CVSS 2.0 High EPSS 55% · top 1.0% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allow remote attackers to execute arbitrary code via (1) a crafted packet or (2) data that ostensibly arrives from the MsgSys.exe process.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with a CVSS 2.0 base score of 9.3 and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.

What it is

IAO.EXE in the Symantec Alert Originator Service (Alert Management System 2, shipped with System Center, AntiVirus, Client Security and Endpoint Protection) contains multiple stack-based buffer overflows. A remote attacker can trigger them with a crafted packet or with data that appears to come from the MsgSys.exe process, leading to arbitrary code execution on the affected host.

Impact

Successful exploitation lets a remote attacker execute arbitrary code with the privileges of the vulnerable service, typically SYSTEM on the management or server host. That gives full control of the machine and, given the products involved, a foothold in the security management infrastructure.

Attack surface

Reached over the network via the Alert Originator Service listening port; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required, though some attack complexity or conditions apply. No user interaction is described.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.55088 (98.98th percentile), indicating a high modeled likelihood of exploitation activity. The record does not confirm public exploit code.

What to do

  • Apply the Symantec vendor updates referenced in the advisory (SAV 9.0 MR7, 10.1 MR8, 10.2 MR2, SCS 2.0 MR7 / 3.1 MR8, SEP 11.0 MR3 or later).
  • If the Alert Management System is not required, disable or uninstall the Intel Alert Originator Service and block its listening port.
  • Restrict network access to the AMS service port to trusted management hosts only, using host firewalls or segmentation.
  • Monitor Symantec advisories for end-of-life status and migrate off unsupported AMS2-based products.
  • Run the service under a least-privilege account where the product permits, to limit post-exploitation impact.

Detection

  • Monitor for crashes or restarts of IAO.EXE and MsgSys.exe on Symantec management and server hosts.
  • Alert on unexpected inbound connections to the Alert Originator Service port from hosts outside the management subnet.
  • Hunt for child processes spawned by IAO.EXE, which would indicate code execution inside the service.
  • Review Windows application and System event logs for service faults and buffer-overflow-related exception codes on affected hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-1430 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0108Symantec antivirus memory buffer overflow vulnerabilityBuffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9…EPSS 19%10.0CVE-2009-1429Symantec AMS2 Intel LANDesk CBA Remote Command ExecutionThe Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2) passes crafted packet contents directly to the CreateProcessA …EPSS 88%analysed10.0CVE-2006-2630Symantec Antivirus and Client Security stack buffer overflowSymantec Antivirus 10.1 and Client Security 3.1 contain a stack-based buffer overflow that remote attackers can trigger through unspecified attack ve…EPSS 74%analysed10.0CVE-2004-0444Symantec client firewall vulnerabilityMultiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 throug…EPSS 13%9.8CVE-2016-3645Symantec norton security vulnerabilityInteger overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…EPSS 25%9.3CVE-2012-4953Symantec antivirus memory buffer overflow vulnerabilityThe decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corpor…EPSS 6.0%9.3CVE-2012-0295Symantec endpoint protection code injection vulnerabilityThe Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-…EPSS 4.0%9.3CVE-2011-0688Symantec antivirus improper authentication vulnerabilityIntel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Cente…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2009-1430), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.