CVE-2009-5151: High severity computrace vulnerability
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allows a privileged local user to achieve persistent control of BIOS behavior, independent of later disk changes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5151?
CVE-2009-5151 has a critical severity rating due to its potential to allow unauthorized code execution on the BIOS.
How do I fix CVE-2009-5151?
To fix CVE-2009-5151, update the Absolute Computrace Agent to the latest version that addresses this vulnerability.
What systems are affected by CVE-2009-5151?
CVE-2009-5151 specifically affects Absolute Computrace Agent version 70.785 on systems where it is installed.
What types of attacks can be executed due to CVE-2009-5151?
CVE-2009-5151 allows attackers to execute arbitrary code on the BIOS, potentially leading to persistent control over system behavior.
Who is at risk from CVE-2009-5151?
Privileged local users who have access to systems with Absolute Computrace Agent version 70.785 are at risk from CVE-2009-5151.