Code Execution Vulnerability in Absolute Computrace Agent by Absolute Software
CVE-2009-5151

6.7MEDIUM

Key Information:

Vendor

Absolute

Vendor
CVE Published:
11 May 2018

What is CVE-2009-5151?

The stub component of Absolute Computrace Agent V70.785 poses a significant security risk by executing arbitrary code from a disk's inter-partition space without requiring a digital signature. This vulnerability allows a privileged local user to execute harmful code directly in the BIOS environment, ensuring persistent control over the BIOS behavior, which remains unaffected by subsequent changes to the disk. As a result, attackers could exploit this flaw to maintain a foothold on the system, potentially compromising its integrity and security.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.