7.2
CVSSv2

CVE-2009-5150

Published: 11/05/2018 Updated: 14/06/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows malicious users to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to execute arbitrary code even after that user loses access and all disk partitions are reformatted.

Vulnerable Product Search on Vulmon Subscribe to Product

absolute computrace agent 80.845

absolute computrace agent 80.866