First published: Wed Aug 17 2005(Updated: )
AOL Client Software 9.0 uses insecure permissions for its installation path, which allows local users to execute arbitrary code with SYSTEM privileges by replacing ACSD.exe with a malicious program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AOL Client Software | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2597 is rated as a high-severity vulnerability due to the potential for local users to execute arbitrary code with SYSTEM privileges.
To fix CVE-2005-2597, ensure that the installation path of AOL Client Software 9.0 has secure permissions and restrict access to the executable file.
CVE-2005-2597 affects users of AOL Client Software version 9.0 who have local access to the machine.
CVE-2005-2597 enables local users to perform code execution attacks by replacing a critical executable with a malicious program.
The impact of CVE-2005-2597 includes the potential compromise of system integrity and confidentiality due to unauthorized code execution.