CVE-2009-4606
Last modified
CVE-2009-4606 is a vulnerability of currently unknown severity. South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| South River Technologies | Webdrive | 9.02 | Build 2232 |
References
- http://secunia.com/advisories/37083Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2994Vendor Advisory
- http://secunia.com/advisories/37083Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2994Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4606?
How severe is CVE-2009-4606?
How do I fix CVE-2009-4606?
Are you affected by CVE-2009-4606?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
