← Vulnerability feed

Vulnerability record · CVE-2009-3031 · published 3 November 2009

CVE-2009-3031: Symantec Altiris ConsoleUtilities ActiveX stack buffer overflow

Symantec · Altiris Deployment Solution

The BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control (AeXNSConsoleUtilities.dll) contains a stack-based buffer overflow triggered by a long string in the second argument. It affects Symantec Altiris Notification Server 6.0 before R12, Deployment Server 6.8/6.9 in Deployment Solution 6.9 SP3, and Symantec Management Platform 7.0 before SP3. Successful exploitation allows remote code execution in the context of the process hosting the control.

9.3 CVSS 2.0 High EPSS 45% · top 1.2% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
14References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec Management Platform (SMP) 7.0 before SP3 allows remote attackers to execute arbitrary code via a long string in the second argument.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote code execution with full impact and public exploit references, but exploitation requires a user to load the vulnerable ActiveX control and the product is an older management platform.

What it is

The BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control (AeXNSConsoleUtilities.dll) contains a stack-based buffer overflow triggered by a long string in the second argument. It affects Symantec Altiris Notification Server 6.0 before R12, Deployment Server 6.8/6.9 in Deployment Solution 6.9 SP3, and Symantec Management Platform 7.0 before SP3. Successful exploitation allows remote code execution in the context of the process hosting the control.

Impact

An attacker can execute arbitrary code on a vulnerable host, typically with the privileges of the user or application that loaded the ActiveX control. Given the CVSS 2.0 vector (C:C/I:C/A:C), full compromise of confidentiality, integrity and availability is possible.

Attack surface

The vector AV:N/AC:M/Au:N indicates the flaw is reachable over the network without authentication, but with medium access complexity. Because the vulnerable component is an ActiveX control, exploitation normally requires a victim to load a page or document that instantiates the control, so user interaction is likely needed even though the CVSS vector does not encode it.

Exploitation

The record is not listed in CISA KEV, but EPSS is high (0.45435, 98.7th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the vendor patches referenced in the Symantec advisory and Altiris KB articles (49389, 49568) to upgrade Notification Server, Deployment Solution and Symantec Management Platform to fixed versions.
  • Disable or remove the Altiris eXpress NS ConsoleUtilities ActiveX control (AeXNSConsoleUtilities.dll) where it is not required, and set kill-bit for the control in Internet Explorer.
  • Restrict access to Altiris/Symantec Management Platform consoles and servers to trusted management networks only.
  • Enforce browser and email controls that block untrusted ActiveX content, and educate users not to open unsolicited pages or documents that load the control.

Detection

  • Monitor for processes loading AeXNSConsoleUtilities.dll, especially from browser or Office processes, and for crashes in that module.
  • Hunt for network or file artifacts matching the public exploit references (sotiriu.de NSOADV-2009-001, SecurityFocus BID 36698).
  • Review endpoint logs for unexpected child processes spawned by browsers or document readers on systems with Altiris management agents installed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-3031 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-3179Symantec altiris deployment solution vulnerabilityMultiple unspecified vulnerabilities in Symantec Altiris Deployment Solution 6.9 might allow remote attackers to execute arbitrary code via unknown c…EPSS 5.3%9.3CVE-2009-3033Symantec altiris deployment solution memory buffer overflow vulnerabilityBuffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in S…EPSS 40%9.3CVE-2009-3109Symantec altiris deployment solution vulnerabilityUnspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication …EPSS 3.8%9.3CVE-2008-4564Autonomy keyview export sdk memory buffer overflow vulnerabilityStack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) produ…EPSS 6.8%7.8CVE-2009-3178Symantec altiris deployment solution vulnerabilityUnspecified vulnerability in mm.exe in Symantec Altiris Deployment Solution 6.9 allows remote attackers to cause a denial of service via unknown atta…EPSS 2.6%7.8CVE-2008-6827Symantec altiris deployment solution missing authentication for critical function vulnerabilityThe ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM…EPSS 1.1%7.8CVE-2008-6828Symantec altiris deployment solution cleartext storage of sensitive data vulnerabilitySymantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows loc…EPSS 0.25%7.5CVE-2008-2286Symantec altiris deployment solution sql injection vulnerabilitySQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute…EPSS 33%

Source: NIST National Vulnerability Database (record CVE-2009-3031), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.