CVE-2009-3489 Information
Feb 14, 2021
cve
Description
Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor which allows local users to (1) stop the service via the stop command (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable or (3) restart the service via the start command.
Reference
http://blogs.adobe.com/psirt/2009/09/potential_photoshop_elements_8.html http://retrogod.altervista.org/9sg_adobe_pe_local.html http://secunia.com/advisories/36895 http://www.securityfocus.com/archive/1/506806/100/0/threaded http://www.securityfocus.com/bid/36542 http://www.securitytracker.com/id?1022963 http://www.vupen.com/english/advisories/2009/2798
Share on: