Vulnerability Description
Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Captivate | All versions |
| Adobe | Contribute | 2 |
| Adobe | Director | All versions |
| Adobe | Dreamweaver | 9.0 |
| Adobe | Elicensing | All versions |
| Adobe | Fireworks | 9.0 |
| Adobe | Flash Player | All versions |
| Adobe | Freehand | mx |
| Adobe | Studio | mx |
References
- http://secunia.com/advisories/15654
- http://securitytracker.com/id?1014158
- http://securitytracker.com/id?1014159
- http://securitytracker.com/id?1014160
- http://securitytracker.com/id?1014161
- http://securitytracker.com/id?1014162
- http://securitytracker.com/id?1014163
- http://securitytracker.com/id?1014164
- http://securitytracker.com/id?1014165
- http://securitytracker.com/id?1014166
- http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf
- http://www.kb.cert.org/vuls/id/953860US Government Resource
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-04.htmlPatchVendor Advisory
- http://www.osvdb.org/17248
- http://www.securityfocus.com/archive/1/423587/100/0/threaded
FAQ
What is CVE-2005-4708?
CVE-2005-4708 is a vulnerability with a CVSS score of 7.2 (HIGH). Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, includ...
How severe is CVE-2005-4708?
CVE-2005-4708 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-4708?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Captivate, Adobe Contribute, Adobe Director, Adobe Dreamweaver, Adobe Elicensing.