Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4351 articles · 196366 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-15379PATCHED
broadcom · symantec it management suite

Arbitrary File Read as SYSTEM in Symantec ITMS

Description

The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller. Any local standard user can therefore read SYSTEM-readable files — including configuration files, service logs, and secrets stored with SYSTEM/Administrator-only ACLs — by querying the provider directly.

Affected Products

VendorProductVersions
broadcomsymantec it management suitebefore SMA_SMP_8_8_PF_v13 and SMA_SMP_8_8_1_PF_v5

References

  • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37995(vendor-advisory)

Related News (1 articles)

Tier C
VulDB38d ago
CVE-2026-15379 | Broadcom Symantec IT Management Suite 8.8/8.8.1 WMI Provider information disclosure
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37995
PublishedJul 17, 2026
Last enriched38d agov2
Tags
information-disclosurewmi-providercve-2026-15379
Trending Score0
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-57220
RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
Trending: 1
CRITICALPRE-CVE
Multiple vulnerabilities in Broadcom VMware Tanzu Greenplum and RabbitMQ products
NONECVE-2026-15380
Local privilege escalation in Symantec ITMS
CRITICALPRE-CVE
Critical Vulnerabilities in VMware Tanzu for MySQL on Kubernetes
NONECVE-2026-11626
Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal Tool

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 17, 2026
Discovered by ZDM
Jul 17, 2026
Updated: severity, cweIds, tags
Jul 17, 2026
Patch Available
Jul 21, 2026

Version History

v2
Last enriched 38d ago
v2Tier C38d ago

Updated severity to HIGH (from NONE), added CWE-284 for improper access control, and added information disclosure and CVE-2026-15379 tags

severitycweIdstags
via VulDB
v138d ago

Initial creation