A critical security vulnerability has been identified in Symantec Endpoint Management , which allows remote code execution without authentication, creating serious risks to enterprise IT infrastructures.
See also: Call of Duty players hack other players via RCE vulnerability

The issue, which is codenamed CVE-2025-5333 and has a high severity rating (CVSS v4.0) of 9.5, affects multiple versions of the popular endpoint management solution and has led to immediate mitigation recommendations from security experts. The vulnerability is located in the Symantec Altiris Inventory Rule Management (IRM), which exploits an outdated and exposed .NET Remoting endpoint at tcp://:4011/IRM/HostedService.
The CVSS score (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) indicates that the exploit is network-based, requiring no user authentication or interaction. Affected product versions include Symantec Endpoint Management Suite 8.6.x, 8.7.x , and 8.8.
The vulnerability results from unsafe deserialization of .NET objects via the BinaryServerFormatterSinkProvider, with the TypeFilterLevel set to Full — a setting that allows uncontrolled deserialization of objects. This allows attackers to create malicious .NET objects, which, when processed by the vulnerable server, lead to arbitrary code execution.
See also: ManageEngine Exchange Reporter Plus vulnerability allows RCE
LRQA security researchers discovered the vulnerability during a Red Team exercise after identifying exposed processes on a hardened system. Analysis with the DnSpy for .NET revealed the use of the RemotingConfiguration.RegisterWellKnownServiceType, confirming the presence of outdated .NET Remoting technology.

The researchers successfully demonstrated the exploit using James Forshaw 's ExploitRemotingService tool , with the command: *ExploitRemotingService.exe –uselease tcp://:4011/IRM/HostedService ls C:*
The Broadcom PSIRT team responded promptly to the coordinated disclosure of the vulnerability, confirming that, according to the official documentation, port 4011 is not required for normal system operation.
The basic mitigation method involves ensuring that firewalls block access to port 4011 on Notification Servers, thereby preventing remote exploitation.
Additionally, it is recommended to set the IRM_HostedServiceUrl to an empty value and restart the Altiris Inventory Rule Management. Broadcom has committed to restricting access to .NET Remoting to only allow access from the local system (localhost) in future releases.
See also: Critical vulnerability in Roundcube allows RCE execution
Organizations using affected versions should immediately review their firewall settings and implement the recommended security measuresto prevent the potential exploitation of this critical vulnerability.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
