CVE-2009-5152
Last modified
CVE-2009-5152 is a vulnerability of currently unknown severity. Absolute Computrace Agent, as distributed on certain Dell Inspiron systems through 2009, has a race condition with the Dell Client Configuration Utility (DCCU), which allows privileged local users to change Computrace Agent's activation/deactivation status to the factory default via a crafted TaskResult.xml file.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Absolute Computrace Agent, as distributed on certain Dell Inspiron systems through 2009, has a race condition with the Dell Client Configuration Utility (DCCU), which allows privileged local users to change Computrace Agent's activation/deactivation status to the factory default via a crafted TaskResult.xml file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Absolute | Computrace Agent | All versions |
References
- https://www.coresecurity.com/system/files/publications/2016/05/Paper-Deactivate-the-Rootkit-AOrtega-ASacco.pdfExploit, Technical Description, Third Party Advisory
- https://www.coresecurity.com/system/files/publications/2016/05/Paper-Deactivate-the-Rootkit-AOrtega-ASacco.pdfExploit, Technical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-5152?
How severe is CVE-2009-5152?
How do I fix CVE-2009-5152?
Are you affected by CVE-2009-5152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
