vendor:
Adobe Photoshop Elements
by:
Nine:Situations:Group::bellick
N/A
CVSS
N/A
Bad Security Descriptor Local Elevation Of Privileges
CWE
Product Name: Adobe Photoshop Elements
Affected Version From: Adobe Photoshop Elements 8.0
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
Unknown
Adobe Photoshop Elements 8.0 Active File Monitor Service Bad Security Descriptor Local Elevation Of Privileges
The "Adobe Active File Monitor V8" service is installed with an improper security descriptor. A malicious user of the Users group (which on xp means a "limited account") can stop the service, then invoke the "sc config" command to replace the binary path with a value of choice, then restart the service to run the command with SYSTEM privileges.
Mitigation:
Change the security descriptor of the service to restrict permissions for unauthorized users.