Arbitrary Code Execution Vulnerability in Absolute Computrace Agent
CVE-2009-5150

6.7MEDIUM

Key Information:

Vendor

Absolute

Vendor
CVE Published:
11 May 2018

What is CVE-2009-5150?

The Absolute Computrace Agent versions V80.845 and V80.866 contain a vulnerability that allows a privileged local user to execute arbitrary code. This occurs due to the absence of a digital signature for the configuration block, enabling attackers to manipulate data within a disk's inter-partition space. Consequently, attackers can establish communication with unauthorized websites instead of the intended search.namequery.com. This vulnerability persists even if the privileged user's access is revoked or if all disk partitions are reformed.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.