Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-5150

Опубликовано: 11 мая 2018
Источник: nvd
CVSS3: 6.7
CVSS2: 7.2
EPSS Низкий

Описание

Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to execute arbitrary code even after that user loses access and all disk partitions are reformatted.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:absolute:computrace_agent:80.845:*:*:*:*:*:*:*
cpe:2.3:a:absolute:computrace_agent:80.866:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00062
Низкий

6.7 Medium

CVSS3

7.2 High

CVSS2

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.7
github
почти 4 года назад

Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to execute arbitrary code even after that user loses access and all disk partitions are reformatted.

EPSS

Процентиль: 20%
0.00062
Низкий

6.7 Medium

CVSS3

7.2 High

CVSS2

Дефекты

CWE-284