Symantec releases patch for application delivery program
Symantec and the U.S. Computer Emergency Readiness Team are warning about a serious vulnerability within the company's AppStream product, used for steaming applications from a central server to thin-client desktops, though a patch has been released.
The product affected is AppStream version 5.2, which is part of the Symantec Endpoint Virtualization Suite formerly known as Software Virtualization Solution (SVS) Pro.
The problem lies in the LaunchObj ActiveX control, which fails to validate external input when called on by an unauthorized server. CERT wrote in a brief advisory on Friday that if a user can be convinced into viewing a specially crafted HTML (Hypertext Markup Language) document, a hacker could execute arbitrary code with the privileges of that user.
Symantec has created an update to fix the problem and advised administrators to apply it.
Both Symantec and CERT discovered the flaw, which Symantec rated as "high" severity. However, it appears that no exploits have been publicly released.
Symantec acquired AppStream in April 2008. Symantec had sold the AppStream software since 2006.
IDG News Service
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
On Twitter now
symantec
Powered by Twitter
jfruh
Apple syncing patent can't come soon enough
pasmith
New Twitter features borrow from 3rd party clients
Esther Schindler
Open Source Changes the Software Acquisition Process
mikelgan
How to set up continuous podcast play on the new iTunes
David Strom
Five important Windows 7 mobility features
sjvn
Guard your Wi-Fi for your own sake
Sandra Henry-Stocker
Grepping on Whole Words
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.












