Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom symantec Server Management Suite |
|
| Vendors & Products |
Broadcom
Broadcom symantec Server Management Suite |
Sun, 26 Jul 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 22 Jul 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Tue, 21 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 |
Fri, 17 Jul 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Jul 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller. Any local standard user can therefore read SYSTEM-readable files — including configuration files, service logs, and secrets stored with SYSTEM/Administrator-only ACLs — by querying the provider directly. | |
| Title | Arbitrary File Read as SYSTEM in Symantec ITMS | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: symantec
Published:
Updated: 2026-07-21T14:15:20.358Z
Reserved: 2026-07-10T09:09:15.879Z
Link: CVE-2026-15379
Updated: 2026-07-17T10:09:56.179Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T20:15:05Z
-
CWE-269
Improper Privilege Management