Back to Database
Status published
High
CVE-2025-9059
Elevation of Privileges Vulnerability in IT Management Suite
Vulnerability Description
The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9059
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Sandro Poppi
More from Broadcom
View All →CVE-2025-8661
Stored Cross-Site Scripting in Symantec PGP Encryption 11.0.1
Medium
4.6
CVE-2025-8660
Privilege Escalation in Symantec PGP Encryption 11.0.1
Medium
5.6
CVE-2025-7398
Medium Strength Cipher Suites detected on port on ports 9000 and 8036
High
8.6
CVE-2025-7397
CLI history displays inline passwords
Medium
6.8
CVE-2025-6392
Daily Data Dump Collector logs database password in cleartext when running docker exec commands (CVE-2025-6392)
Medium
6.7
Affected Vendor
Broadcom
View all reports →Affected Software
8.6.IT Management Suite
Vulnerable Versions:
8.6.x, 8.7.x, 8.8
Timeline
Official Publish:
September 11th, 2025
Last Modified:
September 11th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
MITRE ATT&CK TTPs
T1574
Hijack Execution Flow
Persistence
T1574.001
DLL Search Order Hijacking
Privilege Escalation
T1547
Boot or Logon Autostart Execution
Persistence
T1036
Masquerading
Defense Evasion
T1059
Command and Scripting Interpreter
Execution
T1078
Valid Accounts
Persistence
T1098
Account Manipulation
Privilege Escalation
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1222
File and Directory Permissions Modification
Defense Evasion
T1134
Access Token Manipulation
Defense Evasion