CVE-2009-2027: High severity Safari vulnerability
Published Jun 10, 2009
·Updated
The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the application after installation, related to an unspecified compression method.
Affected Software
12 affected components
Safari=3.2
Safari=3.0.1
Safari=3.1.2
Safari<=3.2.3
Safari=3.0.3
Safari=3.0.2
Safari=3.1.1
Safari=3.0
Safari=3.1
Safari=3.2.2
Safari=3.2.1
Safari=3.0.4
Remediation
Patch Available
Event History
Jun 10, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2027?
CVE-2009-2027 is considered a moderate severity vulnerability due to the potential for privileged escalation.
2
How do I fix CVE-2009-2027?
To fix CVE-2009-2027, upgrade Apple Safari to version 4.0 or later on Windows.
3
What versions of Apple Safari are affected by CVE-2009-2027?
CVE-2009-2027 affects Apple Safari versions prior to 4.0 on Windows.
4
Can local users exploit CVE-2009-2027?
Yes, local users can exploit CVE-2009-2027 by selecting an option that launches the application immediately post-installation.
5
What impact does CVE-2009-2027 have on system security?
CVE-2009-2027 may allow unauthorized local users to gain elevated privileges, compromising system security.