RSS   Vulnerabilities for 'Computrace agent'   RSS

2018-05-11
 
CVE-2009-5152

CWE-362
 

 
Absolute Computrace Agent, as distributed on certain Dell Inspiron systems through 2009, has a race condition with the Dell Client Configuration Utility (DCCU), which allows privileged local users to change Computrace Agent's activation/deactivation status to the factory default via a crafted TaskResult.xml file.

 
 
CVE-2009-5151

CWE-284
 

 
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allows a privileged local user to achieve persistent control of BIOS behavior, independent of later disk changes.

 
 
CVE-2009-5150

CWE-284
 

 
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to execute arbitrary code even after that user loses access and all disk partitions are reformatted.

 

 >>> Vendor: Absolute 2 Products
Computrace agent
Ctes windows agent


Copyright 2019, cxsecurity.com

 

Back to Top