The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller. Any local standard user can therefore read SYSTEM-readable files — including configuration files, service logs, and secrets stored with SYSTEM/Administrator-only ACLs — by querying the provider directly.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-17 08:16
Updated : 2026-07-21 15:16
NVD link : CVE-2026-15379
Mitre link : CVE-2026-15379
CVE.ORG link : CVE-2026-15379
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management
