Impact
The Altiris WMI provider exposes a class named AltirisAgent_Stream that allows any local standard user to read the contents of any file that is accessible to the SYSTEM account, bypassing normal filesystem access control lists. The provider runs with the LocalSystem context when handling WMI queries and does not impersonate the calling user. Consequently, a user with only standard privileges can read files that are normally protected by SYSTEM or Administrator‑only ACLs, such as configuration files, service logs, or secrets.
Affected Systems
This vulnerability affects the Broadcom Symantec IT Management Suite, also known as Symantec ITMS. No specific version information is available, so all deployments using the Altiris WMI provider that have not applied a patch may be exposed.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, while the EPSS score of less than 1% signals a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the issue locally from any standard user account without requiring administrative privileges; the attack path involves querying the AltirisAgent_Stream class via WMI. Because the exploitation requires local access, the threat is limited to machines where standard users can log in, but the potential impact of leaking SYSTEM‑protected data is significant.
OpenCVE Enrichment