PT-2005-5373 · Adobe · Elicensing Client+5
Published
2005-12-31
·
Updated
2018-10-19
·
CVE-2005-4708
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client
Description
The issue allows local users to execute arbitrary code as Local System due to the Macromedia Licensing Service being installed with the Users group permitted to configure the service, including the path to the executable.
Recommendations
For Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client, consider restricting the permissions of the Macromedia Licensing Service to prevent local users from configuring the service and executing arbitrary code.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macromedia Mx 2004
Captivate
Contribute 2
Contribute 3
Macromedia Licensing Service
Elicensing Client