HomeSecurityVulnerability in Symantec Endpoint Management Suite allows RCE execution

Vulnerability in Symantec Endpoint Management Suite allows RCE execution

A critical security vulnerability has been identified in Symantec Endpoint Management , which allows remote code execution without authentication, creating serious risks to enterprise IT infrastructures.

See also: Call of Duty players hack other players via RCE vulnerability

Symantec Endpoint Vulnerability

The issue, which is codenamed CVE-2025-5333 and has a high severity rating (CVSS v4.0) of 9.5, affects multiple versions of the popular endpoint management solution and has led to immediate mitigation recommendations from security experts. The vulnerability is located in the Symantec Altiris Inventory Rule Management (IRM), which exploits an outdated and exposed .NET Remoting endpoint at tcp://:4011/IRM/HostedService.

The CVSS score (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) indicates that the exploit is network-based, requiring no user authentication or interaction. Affected product versions include Symantec Endpoint Management Suite 8.6.x, 8.7.x , and 8.8.

The vulnerability results from unsafe deserialization of .NET objects via the BinaryServerFormatterSinkProvider, with the TypeFilterLevel set to Full — a setting that allows uncontrolled deserialization of objects. This allows attackers to create malicious .NET objects, which, when processed by the vulnerable server, lead to arbitrary code execution.

See also: ManageEngine Exchange Reporter Plus vulnerability allows RCE

LRQA security researchers discovered the vulnerability during a Red Team exercise after identifying exposed processes on a hardened system. Analysis with the DnSpy for .NET revealed the use of the RemotingConfiguration.RegisterWellKnownServiceType, confirming the presence of outdated .NET Remoting technology.

Vulnerability in Symantec Endpoint Management Suite allows RCE execution
Vulnerability in Symantec Endpoint Management Suite allows RCE execution

The researchers successfully demonstrated the exploit using James Forshaw 's ExploitRemotingService tool , with the command: *ExploitRemotingService.exe –uselease tcp://:4011/IRM/HostedService ls C:*

The Broadcom PSIRT team responded promptly to the coordinated disclosure of the vulnerability, confirming that, according to the official documentation, port 4011 is not required for normal system operation.

The basic mitigation method involves ensuring that firewalls block access to port 4011 on Notification Servers, thereby preventing remote exploitation.

Additionally, it is recommended to set the IRM_HostedServiceUrl to an empty value and restart the Altiris Inventory Rule Management. Broadcom has committed to restricting access to .NET Remoting to only allow access from the local system (localhost) in future releases.

See also: Critical vulnerability in Roundcube allows RCE execution

Organizations using affected versions should immediately review their firewall settings and implement the recommended security measuresto prevent the potential exploitation of this critical vulnerability.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS