Vulnerability Description
AOL Client Software 9.0 uses insecure permissions for its installation path, which allows local users to execute arbitrary code with SYSTEM privileges by replacing ACSD.exe with a malicious program.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aol | Aol Client Software | 9.0 |
References
- http://archives.neohapsis.com/archives/ntbugtraq/2005-08/0009.html
- http://www.securityfocus.com/bid/14530
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24324
- http://archives.neohapsis.com/archives/ntbugtraq/2005-08/0009.html
- http://www.securityfocus.com/bid/14530
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24324
FAQ
What is CVE-2005-2597?
CVE-2005-2597 is a vulnerability with a CVSS score of 7.2 (HIGH). AOL Client Software 9.0 uses insecure permissions for its installation path, which allows local users to execute arbitrary code with SYSTEM privileges by replacing ACSD.exe with a malicious program.
How severe is CVE-2005-2597?
CVE-2005-2597 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2597?
Check the references section above for vendor advisories and patch information. Affected products include: Aol Aol Client Software.