PT-2018-4024 · Dell+1 · Dell Client Configuration Utility+1
Published
2018-05-11
·
Updated
2018-06-14
·
CVE-2009-5152
CVSS v2.0
1.9
Low
| Vector | AV:L/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Dell Inspiron systems' Absolute Computrace Agent (affected versions not specified)
Description
The issue is related to a race condition between the Absolute Computrace Agent and the Dell Client Configuration Utility (DCCU). This condition allows privileged local users to modify the activation or deactivation status of the Computrace Agent to its factory default setting by creating a crafted TaskResult.xml file.
Recommendations
For the affected Dell Inspiron systems, consider restricting access to the TaskResult.xml file to prevent unauthorized modifications until a fix is available. As a temporary workaround, monitor the system for any suspicious changes to the Computrace Agent's status. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Absolute Computrace Agent
Dell Client Configuration Utility