Altiris is a systems management and deployment vendor whose tracked vulnerability profile centers on its Client Service and deployment solution products, which operate in the endpoint and infrastructure management domain. The observed weakness classes, including path-traversal flaws, reflect input-handling issues characteristic of administrative tools that interact with file systems and user-supplied configuration inputs; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Altiris over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3874HIGH Directory traversal vulnerability in the tftp/mftp daemon in the PXE server component (pxemtftp.exe) in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows remote atta | Nov 6, 2007 | 7.8 | 26 | NO | NO |
CVE-2004-2622HIGH AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers t | Dec 31, 2004 | 10.0 | 25 | NO | NO |
CVE-2005-1590MEDIUM The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Al | May 16, 2005 | 4.6 | 21 | NO | YES |
CVE-2004-2070HIGH The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File opti | Dec 31, 2004 | 7.2 | 18 | NO | NO |
CVE-2004-1624HIGH Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help t | Oct 21, 2004 | 7.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Altiris.
Media articles that mention a CVE ID that affects a product developed by Altiris — matched by CVE ID, not by vendor name.