← Vulnerability feed

Vulnerability record · CVE-2009-3035 · published 2 February 2010

CVE-2009-3035: Symantec altiris notification server vulnerability

Symantec · Altiris Notification Server

The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials.

4.3 CVSS 2.0 Medium EPSS 0.37% · top 71.4% CWE-255 · CWE-255
4.3CVSS 2.0 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials.

AV:L/AC:L/Au:S/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-3035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-3033Symantec altiris deployment solution memory buffer overflow vulnerabilityBuffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in S…EPSS 40%9.3CVE-2009-3031Symantec Altiris ConsoleUtilities ActiveX stack buffer overflowThe BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control (AeXNSConsoleUtilities.dll) contains a stack-based buffer ove…EPSS 45%analysed6.8CVE-2009-3028Symantec altiris deployment solution vulnerabilityThe Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6…EPSS 43%6.8CVE-2008-2794Symantec altiris notification server permissions and access controls vulnerabilityUnspecified vulnerability in the GUI in Symantec Altiris Notification Server Agent 6.x before 6.0 SP3 R8 allows local users to gain privileges via un…EPSS 0.31%6.8CVE-2008-0716Symantec altiris notification server vulnerabilityThe agent in Symantec Altiris Notification Server before 6.0 SP3 R7 allows local users to gain privileges via a "Shatter" style attack.EPSS 0.30%8.8CVE-2014-1812Microsoft Windows Group Policy Preferences credential exposure and privilege escalationGroup Policy Preferences in multiple Windows versions stored and distributed passwords in a way that did not properly protect them, allowing any auth…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2009-3035), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.