CVE-2025-9059
BaseFortify
Publication date: 2025-09-11
Last updated on: 2025-09-11
Assigner: Symantec Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| symantec | altiris_core_agent_updater | 4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-427 | The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. |
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an elevation of privileges issue in the Altiris Core Agent Updater package (AeXNSC.exe) caused by DLL hijacking. This means that an attacker could exploit the way the software loads DLL files to execute malicious code with higher privileges than intended.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability could gain elevated privileges on the affected system, potentially allowing them to execute arbitrary code with higher permissions, which could lead to unauthorized actions, system compromise, or further attacks.