SymantecAppStream Client ActiveX Insecure Method Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
19 Jan 2009
5356
Views
RISK: Medium Risk
A vulnerability has been identified in Symantec AppStream Client, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by errors in the LaunchObj ActiveX control (launcher.dll) that contains unsafe methods e.g. "installAppMgr()", which can be exploited to download and execute arbitrary code by tricking a user into visiting a malicious web page.
Impact
- Remote Code Execution
System / Technologies affected
- Symantec AppStream Client versions 5.2.x
Solutions
Before installation of the software, please visit the software manufacturerweb-site for more details.
- Upgrade to Symantec AppStream Client version 5.2.2 SP3 MP1 :
http://www.symantec.com/business/software-virtualization-solution-professional
Vulnerability Identifier
Source
Related Link
Share with