Lucene search

K
cveMitreCVE-2009-2564
HistoryJul 21, 2009 - 5:30 p.m.

CVE-2009-2564

2009-07-2117:30:00
CWE-264
mitre
web.nvd.nist.gov
38
cve
2009
2564
nos microsystems
getplus download manager
adobe reader
corel
trojan horse
insecure permissions
local users
system privileges
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

9.8%

NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is limited because the program is deleted and the associated service is not automatically launched after a successful installation and reboot.

Affected configurations

Nvd
Node
nos_microsystemsgetplus_download_managerMatch1.6.2.36
AND
adobeacrobat_readerMatch9.0
OR
adobeacrobat_readerMatch9.1
Node
corelgetplus_download_managerMatch1.5.0.48
VendorProductVersionCPE
nos_microsystemsgetplus_download_manager1.6.2.36cpe:2.3:a:nos_microsystems:getplus_download_manager:1.6.2.36:*:*:*:*:*:*:*
adobeacrobat_reader9.0cpe:2.3:a:adobe:acrobat_reader:9.0:*:*:*:*:*:*:*
adobeacrobat_reader9.1cpe:2.3:a:adobe:acrobat_reader:9.1:*:*:*:*:*:*:*
corelgetplus_download_manager1.5.0.48cpe:2.3:a:corel:getplus_download_manager:1.5.0.48:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

9.8%