Vulnerability record · CVE-2009-3031 · published 3 November 2009
CVE-2009-3031: Symantec Altiris ConsoleUtilities ActiveX stack buffer overflow
Symantec · Altiris Deployment Solution
The BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control (AeXNSConsoleUtilities.dll) contains a stack-based buffer overflow triggered by a long string in the second argument. It affects Symantec Altiris Notification Server 6.0 before R12, Deployment Server 6.8/6.9 in Deployment Solution 6.9 SP3, and Symantec Management Platform 7.0 before SP3. Successful exploitation allows remote code execution in the context of the process hosting the control.
Description
Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec Management Platform (SMP) 7.0 before SP3 allows remote attackers to execute arbitrary code via a long string in the second argument.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with full impact and public exploit references, but exploitation requires a user to load the vulnerable ActiveX control and the product is an older management platform.
What it is
The BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control (AeXNSConsoleUtilities.dll) contains a stack-based buffer overflow triggered by a long string in the second argument. It affects Symantec Altiris Notification Server 6.0 before R12, Deployment Server 6.8/6.9 in Deployment Solution 6.9 SP3, and Symantec Management Platform 7.0 before SP3. Successful exploitation allows remote code execution in the context of the process hosting the control.
Impact
An attacker can execute arbitrary code on a vulnerable host, typically with the privileges of the user or application that loaded the ActiveX control. Given the CVSS 2.0 vector (C:C/I:C/A:C), full compromise of confidentiality, integrity and availability is possible.
Attack surface
The vector AV:N/AC:M/Au:N indicates the flaw is reachable over the network without authentication, but with medium access complexity. Because the vulnerable component is an ActiveX control, exploitation normally requires a victim to load a page or document that instantiates the control, so user interaction is likely needed even though the CVSS vector does not encode it.
Exploitation
The record is not listed in CISA KEV, but EPSS is high (0.45435, 98.7th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Apply the vendor patches referenced in the Symantec advisory and Altiris KB articles (49389, 49568) to upgrade Notification Server, Deployment Solution and Symantec Management Platform to fixed versions.
- Disable or remove the Altiris eXpress NS ConsoleUtilities ActiveX control (AeXNSConsoleUtilities.dll) where it is not required, and set kill-bit for the control in Internet Explorer.
- Restrict access to Altiris/Symantec Management Platform consoles and servers to trusted management networks only.
- Enforce browser and email controls that block untrusted ActiveX content, and educate users not to open unsolicited pages or documents that load the control.
Detection
- Monitor for processes loading AeXNSConsoleUtilities.dll, especially from browser or Office processes, and for crashes in that module.
- Hunt for network or file artifacts matching the public exploit references (sotiriu.de NSOADV-2009-001, SecurityFocus BID 36698).
- Review endpoint logs for unexpected child processes spawned by browsers or document readers on systems with Altiris management agents installed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3031 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3031), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.