{"api_version":"1","generated_at":"2026-07-23T13:12:49+00:00","cve":"CVE-2009-3489","urls":{"html":"https://cve.report/CVE-2009-3489","api":"https://cve.report/api/cve/CVE-2009-3489.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3489","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3489"},"summary":{"title":"CVE-2009-3489","description":"Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-09-30 15:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-732","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.9","severity":"","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2009/2798","name":"http://www.vupen.com/english/advisories/2009/2798","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/506806/100/0/threaded","name":"http://www.securityfocus.com/archive/1/506806/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36542","name":"http://www.securityfocus.com/bid/36542","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Third Party Advisory","VDB Entry"],"title":"Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/36895","name":"http://secunia.com/advisories/36895","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Adobe Photoshop Elements Active File Monitor Service Privilege Escalation - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://retrogod.altervista.org/9sg_adobe_pe_local.html","name":"http://retrogod.altervista.org/9sg_adobe_pe_local.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit"],"title":"Error 404 :(","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1022963","name":"http://www.securitytracker.com/id?1022963","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - Adobe Photoshop Elements Lets Local Users Gain Elevated Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blogs.adobe.com/psirt/2009/09/potential_photoshop_elements_8.html","name":"http://blogs.adobe.com/psirt/2009/09/potential_photoshop_elements_8.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Potential Photoshop Elements 8.0 issue «  Adobe Product Security Incident Response Team (PSIRT) Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3489","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3489","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3489","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"photoshop_elements","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:31:10.303Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"36542","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36542"},{"name":"ADV-2009-2798","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/2798"},{"name":"20090929 Adobe Photoshop Elements 8.0 Active File Monitor Service Bad Security Descriptor Local Elevation Of Privileges","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/506806/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogs.adobe.com/psirt/2009/09/potential_photoshop_elements_8.html"},{"name":"1022963","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1022963"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://retrogod.altervista.org/9sg_adobe_pe_local.html"},{"name":"36895","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36895"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-09-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"36542","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36542"},{"name":"ADV-2009-2798","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/2798"},{"name":"20090929 Adobe Photoshop Elements 8.0 Active File Monitor Service Bad Security Descriptor Local Elevation Of Privileges","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/506806/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://blogs.adobe.com/psirt/2009/09/potential_photoshop_elements_8.html"},{"name":"1022963","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1022963"},{"tags":["x_refsource_MISC"],"url":"http://retrogod.altervista.org/9sg_adobe_pe_local.html"},{"name":"36895","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36895"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-3489","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"36542","refsource":"BID","url":"http://www.securityfocus.com/bid/36542"},{"name":"ADV-2009-2798","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/2798"},{"name":"20090929 Adobe Photoshop Elements 8.0 Active File Monitor Service Bad Security Descriptor Local Elevation Of Privileges","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/506806/100/0/threaded"},{"name":"http://blogs.adobe.com/psirt/2009/09/potential_photoshop_elements_8.html","refsource":"MISC","url":"http://blogs.adobe.com/psirt/2009/09/potential_photoshop_elements_8.html"},{"name":"1022963","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1022963"},{"name":"http://retrogod.altervista.org/9sg_adobe_pe_local.html","refsource":"MISC","url":"http://retrogod.altervista.org/9sg_adobe_pe_local.html"},{"name":"36895","refsource":"SECUNIA","url":"http://secunia.com/advisories/36895"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-3489","datePublished":"2009-09-30T15:00:00.000Z","dateReserved":"2009-09-30T00:00:00.000Z","dateUpdated":"2024-08-07T06:31:10.303Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-09-30 15:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-732","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:photoshop_elements:8.0:*:*:*:*:*:*:*","matchCriteriaId":"218766FE-4F82-4704-BA6A-C0CF1D148DA5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3489","Ordinal":"1","Title":"CVE-2009-3489","CVE":"CVE-2009-3489","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3489","Ordinal":"1","NoteData":"Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.","Type":"Description","Title":"CVE-2009-3489"},{"CveYear":"2009","CveId":"3489","Ordinal":"2","NoteData":"2009-09-30","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3489","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}