Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2010-3268 Details

Description

The GetStringAMSHandler function in prgxhndl.dll in hndlrsvc.exe in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (AMS), as used in Symantec Antivirus Corporate Edition 10.1.4.4010 on Windows 2000 SP4 and Symantec Endpoint Protection before 11.x, does not properly validate the CommandLine field of an AMS request, which allows remote attackers to cause a denial of service (application crash) via a crafted request.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://secunia.com/advisories/42593 CVEVendor Advisory
http://secunia.com/advisories/43099 CVE
https://exchange.xforce.ibmcloud.com/vulnerabilities/64028 CVE
http://www.coresecurity.com/content/symantec-intel-handler-service-remote-dos CVEExploit
http://www.securityfocus.com/archive/1/515191/100/0/threaded CVE

see all 20 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-20Improper Input Validation[email protected]

Affected Products

ProductVersions
intel intel alert management system
All versions

CPE

  • cpe:2.3:a:intel:intel_alert_management_system:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
symantec antivirus
10.1.4.4010

CPE

  • cpe:2.3:a:symantec:antivirus:10.1.4.4010:*:corporate:*:*:*:*:*

Remediation

  • No remediation found in references.
microsoft windows 2000
All versions

CPE

  • cpe:2.3:o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*

Remediation

  • No remediation found in references.
symantec endpoint protection
11.0
11.0 rtm
11.0 ru5
11.0 ru6
11.0 ru6a

CPE

  • cpe:2.3:a:symantec:endpoint_protection:11.0:*:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0:rtm:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0:ru5:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0:ru6:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0:ru6a:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0:ru6mp1:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0:ru6mp2:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0.1:mp1:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0.1:mp2:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0.2:*:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0.2:mp1:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0.2:mp2:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0.4:*:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0.4:mp1a:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0.4:mp2:*:*:*:*:*:*
  • cpe:2.3:a:symantec:endpoint_protection:11.0.3001:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

8 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2010-3268
NVD Published Date:
Dec 22, 2010
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2010-3268 Details - Not Deferred