CVE Database
/

CVE-2009-2564

Back to search

CVE-2009-2564

Published: Jul 21, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is limited because the program is deleted and the associated service is not automatically launched after a successful installation and reboot.

VendorProductVersions

n/a

n/a

affected
n/a

References

9199
exploit
x_refsource_EXPLOIT-DB
TA09-286B
third-party-advisory
x_refsource_CERT
1023007
vdb-entry
x_refsource_SECTRACK
oval:org.mitre.oval:def:5719
vdb-entry
signature
x_refsource_OVAL
35740
vdb-entry
x_refsource_BID
ADV-2009-1969
vdb-entry
x_refsource_VUPEN
35930
third-party-advisory
x_refsource_SECUNIA
ADV-2009-2898
vdb-entry
x_refsource_VUPEN
36331
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now