Vulnerability Description
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to execute arbitrary code even after that user loses access and all disk partitions are reformatted.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Absolute | Computrace Agent | 80.845 |
Related Weaknesses (CWE)
References
- https://www.coresecurity.com/system/files/publications/2016/05/Paper-Deactivate-ExploitTechnical DescriptionThird Party Advisory
- https://www.coresecurity.com/system/files/publications/2016/05/Paper-Deactivate-ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2009-5150?
CVE-2009-5150 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended sear...
How severe is CVE-2009-5150?
CVE-2009-5150 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-5150?
Check the references section above for vendor advisories and patch information. Affected products include: Absolute Computrace Agent.