PT-2018-4024 · Dell+1 · Dell Client Configuration Utility+1

Publicado

2018-05-11

·

Atualizado

2018-06-14

·

CVE-2009-5152

CVSS v2.0

1.9

Baixa

VetorAV:L/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dell Inspiron systems' Absolute Computrace Agent (affected versions not specified)
Description The issue is related to a race condition between the Absolute Computrace Agent and the Dell Client Configuration Utility (DCCU). This condition allows privileged local users to modify the activation or deactivation status of the Computrace Agent to its factory default setting by creating a crafted TaskResult.xml file.
Recommendations For the affected Dell Inspiron systems, consider restricting access to the TaskResult.xml file to prevent unauthorized modifications until a fix is available. As a temporary workaround, monitor the system for any suspicious changes to the Computrace Agent's status. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-5152

Produtos afetados

Absolute Computrace Agent
Dell Client Configuration Utility