PT-2026-60727 · Symantec · Altiris Wmi Provider

CVE-2026-15379

·

Published

2026-07-17

·

Updated

2026-07-21

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y/R:A/V:C/RE:M/U:Red
Name of the Vulnerable Software and Affected Versions Altiris WMI provider (affected versions not specified)
Description The Altiris WMI provider contains a flaw in the AltirisAgent Stream class that allows a local standard user to read files accessible to the SYSTEM account, bypassing filesystem Access Control Lists (ACLs). This occurs because the provider reverts to the LocalSystem context when processing WMI queries instead of re-impersonating the caller. Consequently, users can access sensitive data such as configuration files, service logs, and secrets restricted to SYSTEM or Administrator accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15379

Affected Products

Altiris Wmi Provider