Remote Code Execution in Symantec Alert Management System by Intel File Transfer Service
CVE-2009-1431

Currently unrated

Key Information:

Vendor

Symantec

Vendor
CVE Published:
29 April 2009

What is CVE-2009-1431?

A vulnerability exists in the Intel File Transfer service of the Symantec Alert Management System that allows remote attackers to execute arbitrary code. By placing malicious payloads on a network share or a WebDAV server and providing the UNC share pathname to the vulnerable service, attackers can gain unauthorized access and control over the affected systems. This affects multiple Symantec products, potentially compromising the security of users' environments.

References

EPSS Score

29% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.