PT-2009-5782 · Adobe · Photoshop Elements
CVE-2009-3489
·
Publicado
2009-09-30
·
Atualizado
2024-02-08
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Photoshop Elements version 8.0
Description
The issue allows local users to stop the service, execute arbitrary commands as SYSTEM by modifying the
binPath variable using the config command, or restart the service. This is due to an insecure security descriptor in the Adobe Active File Monitor V8 service installed by Adobe Photoshop Elements.Recommendations
For Adobe Photoshop Elements version 8.0, consider restricting access to the service to prevent unauthorized modifications, and avoid using the config command to modify the
binPath variable until a fix is available. As a temporary workaround, consider disabling the Adobe Active File Monitor V8 service until a patch is available.Exploit
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Photoshop Elements