Symantec Alert Management System HNDLRSVC Arbitrary Command Execution
| TSL ID | FSC20100727-01 |
| CVE ID(s) | Not available. |
| Severity | Critical |
| Description | An arbitrary command execution vulnerability exists in Symantec Alert Management System (AMS2) service installed with multiple Symantec products. The AMS service starts an alert handler service that can be accessed via MsgSys.exe listening on port 38292/TCP and runs with SYSTEM privileges. This service listens for commands from the AMS server, but does not perform proper authentication checks before executing such commands. Remote unauthenticated attackers can exploit this vulnerability by sending a crafted packet to the target service and execute arbitrary programs with the SYSTEM privileges. The vendor has not released any patch to address this vulnerability. As a workaround, disable the HNDLRSVC service on the affected systems. |
| Affected Products |
|
| CVSS Score |
Base 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C):
|