CVE-2009-5151
Last modified
CVE-2009-5151 is a vulnerability of currently unknown severity. The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allows a privileged local user to achieve persistent control of BIOS behavior, independent of later disk changes.. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allows a privileged local user to achieve persistent control of BIOS behavior, independent of later disk changes.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Absolute | Computrace Agent | 70.785 |
References
- https://www.coresecurity.com/system/files/publications/2016/05/Paper-Deactivate-the-Rootkit-AOrtega-ASacco.pdfExploit, Technical Description, Third Party Advisory
- https://www.coresecurity.com/system/files/publications/2016/05/Paper-Deactivate-the-Rootkit-AOrtega-ASacco.pdfExploit, Technical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-5151?
How severe is CVE-2009-5151?
How do I fix CVE-2009-5151?
Are you affected by CVE-2009-5151?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
