Executive brief
A vulnerability in the Symantec IT Management Suite (formerly Altiris) allows a standard user on a computer to read sensitive files they should not have access to. By exploiting a flaw in how the management agent handles data requests, an attacker can view system configuration files, logs, and passwords. This could lead to the theft of administrative credentials or other sensitive corporate data stored on the machine.
Technical details
The Altiris WMI provider exposes a specific class, AltirisAgent_Stream, which fails to properly re-impersonate the calling user when servicing queries. Instead, the provider reverts to the LocalSystem security context. A local attacker with standard user privileges can exploit this by querying the WMI provider to read the contents of any file on the filesystem that is readable by the SYSTEM account, effectively bypassing NTFS Access Control Lists (ACLs). This can be used to extract sensitive configuration files, service logs, or secrets. The vulnerability affects Symantec IT Management Suite versions 8.8 and 8.8.1.
Affected products
- Broadcom Symantec IT Management Suite (Altiris) 8.8, 8.8.1
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory