ignorance isn't always an option

Foofus.net Security Advisory 20100726 - Symantec Antivirus CE Command Execution

Foofus.net Security Advisory 20100726 - Symantec Antivirus CE Command Execution
Posted Jul 26, 2010
Authored by Spider | Site foofus.net

The Symantec Antivirus Corporate Edition AMS Intel Alert Handler service (hndlrsvc.exe) provides alert setup and response capabilities to AMS2. A design error in Symantec's implementation of this function allows an attacker who can establish a TCP connection to port 38292, on a vulnerable host to execute commands at system level on that host. Versions 10.1.8.8000 and below are affected.

tags | advisory, tcp
MD5 | e3cc0c7592f38c3b6586dee82cf27d3e

Foofus.net Security Advisory 20100726 - Symantec Antivirus CE Command Execution

Change Mirror Download
==================================================
Foofus.net Security Advisory: foofus-20100726
==================================================
Title: Symantec Antivirus Corporate Edition AMS Intel Alert Handler

Version: 10.1.8.8000 and earlier

Vendor: Symantec

Release Date: 26.07.2010

Issue Status: Reported To Vendor on 01/06/2010

==================================================



1. Summary:



Alert Management Service (AMS2) is a service used to setup, manage and report

alerts within legacy Symantec Antivirus Corporate Edition products.



==================================================


2. Description:



The Intel Alert Handler service (hndlrsvc.exe) provides alert setup and response

capabilities to AMS2. A design error in Symantec's implementation of this function

allows an attacker who can establish a TCP connection to port 38292, on a vulnerable

host to execute commands at system level on that host.



No special exploit code is needed to carry out this attack, by leveraging the AMS

server console tool an attacker can setup an alert response to run a command on a

vulnerable system without authenticating. The AMS server console can also be used

to remotely trigger the alert causing the command to execute at system level.





==================================================


3. Impact:



Exploiting this allows an adversary to execute code on a vulnerable system with out

authenticating



==================================================



4. Affected Products:



All version of Symantec SAVCE with AMS server installed, or Symantec System CenterConsole

with AMS plugin installed are vulnerable to this exploit.



==================================================


5. Solution:



a. Uninstall Symantec System Center. It is advised that any system vulnerable to

this exploit have all Symantec products uninstalled and reinstalled. Uninstalling

the AMS plugin from an affected installation will not remove the vulnerability.

b. Uninstall AMS server

c. Disable Alert Handler (hndlrsvc.exe) service

d. Also upgrade to the latest version of Symantec Endpoint Protection



==================================================


6) Time Table:



01/06/2010 Reported Vulnerability to Vendor.

01/11/2010 Vendor acknowledged Receiving report

01/12/2010 Vendor Tried to convince me that this was XFR.exe issue

07/26/2010 Publishes Advisory



==================================================



7) Credits: Discovered by SPIDER



==================================================


8. Reference:



http://www.foofus.net/?page_id=149


==================================================


The Foofus.Net team is an assortment of security professionals located somewhere

in the Midwestern United States. http://www.foofus.net



==================================================


Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close