PT-2018-4024 · Dell+1 · Dell Client Configuration Utility+1

Published

2018-05-11

·

Updated

2018-06-14

·

CVE-2009-5152

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dell Inspiron systems' Absolute Computrace Agent (affected versions not specified)
Description The issue is related to a race condition between the Absolute Computrace Agent and the Dell Client Configuration Utility (DCCU). This condition allows privileged local users to modify the activation or deactivation status of the Computrace Agent to its factory default setting by creating a crafted TaskResult.xml file.
Recommendations For the affected Dell Inspiron systems, consider restricting access to the TaskResult.xml file to prevent unauthorized modifications until a fix is available. As a temporary workaround, monitor the system for any suspicious changes to the Computrace Agent's status. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-5152

Affected Products

Absolute Computrace Agent
Dell Client Configuration Utility