Skip to content

Top Stories

Top Stories

Primary Menu
  • Breaking News
  • UNIT CONVERTER
  • QR Code Generator
  • SEO META TAG GENERATOR
  • Background Remover Tool
  • Image Enhancer Tool
  • Image Converter Tool
  • Image Compressor Tool
  • Keyword Research Tool
  • Paint Tool
  • About Us
  • Contact Us
  • Privacy Policy
HOME PAGE
  • Home
  • Uncategorized
  • Critical RCE Vulnerability Found in Symantec Endpoint Management Platform
  • Uncategorized

Critical RCE Vulnerability Found in Symantec Endpoint Management Platform

VedVision HeadLines July 15, 2025
Critical RCE Vulnerability Found in Symantec Endpoint Management Platform


Security researchers at LRQA have uncovered a critical remote code execution (RCE) vulnerability in Broadcom’s Symantec Endpoint Management Suite, formerly known as Altiris, that could allow unauthenticated attackers to execute arbitrary code on vulnerable systems.

The flaw, assigned CVE-2025-5333, affects multiple versions of the widely used enterprise endpoint management platform and has been rated with a critical CVSS score of 9.5.

Vulnerability Overview

The vulnerability stems from an exposed legacy .NET Remoting endpoint in the Symantec Altiris Inventory Rule Management (IRM) component, accessible at tcp://:4011/IRM/HostedService.

When this endpoint is reachable over the network, it enables attackers to exploit insecure deserialization of .NET objects, leading to complete system compromise without requiring authentication.

CVE Details Information
CVE ID CVE-2025-5333
Severity Critical
CVSS v4.0 Score 9.5
CVSS Vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected Product Broadcom Symantec Endpoint Management Suite (Altiris)
Affected Versions 8.6.x, 8.7.x, 8.8

The vulnerability was discovered during a recent Red Team engagement when security researchers gained access to a hardened workstation and began reconnaissance activities.

While examining running processes, they identified Symantec Endpoint Management services and decided to investigate the infrastructure as a potential privilege escalation and lateral movement vector.

Using PowerShell to enumerate listening network services, the researchers found port 4011 bound to 0.0.0.0, indicating global accessibility.

Further investigation using DnSpy, a .NET debugger and assembly editor, revealed that the application was using RemotingConfiguration.RegisterWellKnownServiceType, indicating the presence of legacy .NET Remoting.

The decompiled code showed that the application used BinaryServerFormatterSinkProvider with TypeFilterLevel set to Full, a configuration known to be unsafe as it enables unrestricted object deserialization.

This vulnerability class was originally explored by James Forshaw in 2014 and represents a well-documented attack vector for .NET Remoting services.

Researchers confirmed the vulnerability using Forshaw’s ExploitRemotingService tool, successfully executing commands and retrieving directory contents from the target system remotely.

Following coordinated disclosure procedures, LRQA reported the vulnerability to Broadcom’s Product Security Incident Response Team (PSIRT). Broadcom responded promptly and professionally, confirming the issue and providing mitigation guidance.

The primary mitigation involves ensuring port 4011 is closed on the Notification Server firewall, as official documentation does not require this port to be opened.

Additionally, administrators can configure the IRM_HostedServiceUrl setting to remain empty, restricting .NET Remoting access to localhost only.

Broadcom has indicated that future product releases will include enhanced security measures to limit and secure the use of .NET Remoting for the IRM/HostedService component, preventing remote access to this potentially dangerous endpoint.

Organizations using affected versions should immediately review their firewall configurations and implement the recommended mitigations to prevent exploitation of this critical vulnerability.

Stay Updated on Daily Cybersecurity News . Follow us on Google News, LinkedIn, and X.



Source link

Continue Reading

Previous: Binance Adds Pump.fun-Style Token Launch Model
Next: DMK student wing holds protest – News Today

Related News

Iranian Threat Actors Target U.S. Critical Infrastructure, Including Water Systems
  • Uncategorized

Iranian Threat Actors Target U.S. Critical Infrastructure, Including Water Systems

VedVision HeadLines July 15, 2025
Pope Francis and the soul of economics
  • Uncategorized

Pope Francis and the soul of economics

VedVision HeadLines July 15, 2025
Crypto Custody Made Clear: Joint Guidance From US Banking Regulators Released
  • Uncategorized

Crypto Custody Made Clear: Joint Guidance From US Banking Regulators Released

VedVision HeadLines July 15, 2025

Recent Posts

  • Iranian Threat Actors Target U.S. Critical Infrastructure, Including Water Systems
  • Emmys nominations 2025: ‘The Studio’ breaks records, ‘Andor’ shut out in shocker — full list of nominations
  • Pope Francis and the soul of economics
  • Canadian Seth Rogen’s The Studio leads comedy noms for Primetime Emmys. Here’s who’s vying for TV’s top prize
  • Crypto Custody Made Clear: Joint Guidance From US Banking Regulators Released

Recent Comments

No comments to show.

Archives

  • July 2025
  • June 2025
  • May 2025
  • April 2025

Categories

  • Current Affairs
  • Shopping
  • Uncategorized

You may have missed

Iranian Threat Actors Target U.S. Critical Infrastructure, Including Water Systems
  • Uncategorized

Iranian Threat Actors Target U.S. Critical Infrastructure, Including Water Systems

VedVision HeadLines July 15, 2025
Emmys nominations 2025: ‘The Studio’ breaks records, ‘Andor’ shut out in shocker — full list of nominations
  • Current Affairs

Emmys nominations 2025: ‘The Studio’ breaks records, ‘Andor’ shut out in shocker — full list of nominations

VedVision HeadLines July 15, 2025
Pope Francis and the soul of economics
  • Uncategorized

Pope Francis and the soul of economics

VedVision HeadLines July 15, 2025
Canadian Seth Rogen’s The Studio leads comedy noms for Primetime Emmys. Here’s who’s vying for TV’s top prize
  • Current Affairs

Canadian Seth Rogen’s The Studio leads comedy noms for Primetime Emmys. Here’s who’s vying for TV’s top prize

VedVision HeadLines July 15, 2025
Copyright © All rights reserved. | MoreNews by AF themes.