CVE-2009-2564: High severity getplus download manager vulnerability
NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlusHelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlusHelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is limited because the program is deleted and the associated service is not automatically launched after a successful installation and reboot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2564?
CVE-2009-2564 is considered a moderate severity vulnerability due to its impact on local user permissions.
How do I fix CVE-2009-2564?
To fix CVE-2009-2564, update the affected software versions of Corel getPlus Download Manager and NOS Microsystems getPlus Download Manager to the latest available versions.
What systems are affected by CVE-2009-2564?
CVE-2009-2564 affects NOS Microsystems getPlus Download Manager 1.6.2.36, Corel getPlus Download Manager before 1.5.0.48, and specific versions of Adobe Acrobat Reader.
What are the potential risks associated with CVE-2009-2564?
The potential risks of CVE-2009-2564 include unauthorized access and modifications by local users due to insecure permissions.
Is there a workaround for CVE-2009-2564?
A possible workaround for CVE-2009-2564 is to restrict permissions on the NOS\bin\getPlus_HelperSvc.exe file until an official patch or update can be applied.