SunnComm MediaMax DRM 5.0.21.0, as used by Sony BMG, assigns insecure Everyone/Full Control permissions to the "SunnComm Shared" directory, which allows local users to gain privileges by modifying programs installed in that directory, such as MMX.exe.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2005/2783 | vdb entry vendor advisory |
http://www.eff.org/IP/DRM/Sony-BMG/MediaMaxVulnerabilityReport.pdf | exploit vendor advisory |
http://www.securityfocus.com/bid/15754 | vdb entry |
http://www.eff.org/news/archives/2005_12.php#004234 | |
http://www.kb.cert.org/vuls/id/928689 | third party advisory us government resource |
http://secunia.com/advisories/17933 | third party advisory patch vendor advisory |
http://securitytracker.com/id?1015327 | vdb entry |