CVE-2009-4606
Last modified
CVE-2009-4606 is a vulnerability of currently unknown severity. South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| South River Technologies | Webdrive | 9.02 | Build 2232 |
References
- http://secunia.com/advisories/37083Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2994Vendor Advisory
- http://secunia.com/advisories/37083Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2994Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4606?
How severe is CVE-2009-4606?
How do I fix CVE-2009-4606?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-4600SQL injection vulnerability in realestate20/loginaction.php …
- CVE-2009-4601Cross-site scripting (XSS) vulnerability in basic_search_res…
- CVE-2009-4602Cross-site scripting (XSS) vulnerability in the Randomizer m…
- CVE-2009-4603Unspecified vulnerability in sapstartsrv.exe in the SAP Kern…
- CVE-2009-4604PHP remote file inclusion vulnerability in mamboleto.php in …
- CVE-2009-4605scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.…
- CVE-2009-4607The command line interface in Overland Storage Snap Server 4…
- CVE-2009-4608Cross-site scripting (XSS) vulnerability in Canon IT Solutio…
- CVE-2009-4609The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remo…
- CVE-2009-4610Multiple cross-site scripting (XSS) vulnerabilities in Mort …
- CVE-2009-4611Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace…
- CVE-2009-4612Multiple cross-site scripting (XSS) vulnerabilities in the W…
Are you affected by CVE-2009-4606?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
