Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system, and execute these files, via unspecified vectors.
2010-06-17T16:30:01.293
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | symantec | workspace_streaming | 6.1 | Yes |
Application | symantec | workspace_streaming | 6.1 | Yes |
Application | symantec | workspace_streaming | 6.1 | Yes |
Application | symantec | workspace_streaming | 6.1 | Yes |
Application | symantec | appstream | 5.2 | Yes |
Application | symantec | appstream | 5.2.1 | Yes |
Application | symantec | appstream | 5.2.2 | Yes |
Application | symantec | appstream | 5.2.3 | Yes |