CVE-2009-3489
Last modified
CVE-2009-3489 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.. EPSS estimates a 1.95% chance of exploitation in the next 30 days.
Description
Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Photoshop Elements | 8.0 |
References
- http://retrogod.altervista.org/9sg_adobe_pe_local.htmlBroken Link, Exploit
- http://secunia.com/advisories/36895Broken Link
- http://www.securityfocus.com/archive/1/506806/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/36542Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022963Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/2798Permissions Required
- http://retrogod.altervista.org/9sg_adobe_pe_local.htmlBroken Link, Exploit
- http://secunia.com/advisories/36895Broken Link
- http://www.securityfocus.com/archive/1/506806/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/36542Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022963Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/2798Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3489?
How severe is CVE-2009-3489?
How do I fix CVE-2009-3489?
Are you affected by CVE-2009-3489?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
