CVE-2009-3489 EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.95% — more likely to be exploited than 80% of all CVEs |
| Weakness | CWE-732 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-09-30 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| adobe | photoshop elements |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe Photoshop Elements - Active File Monitor Service Privilege Escalation | 2009-10-29 |
| exploit-db | Adobe Photoshop Elements 8.0 - Active File Monitor Privilege Escalation | 2009-09-29 |
References
- http://blogs.adobe.com/psirt/2009/09/potential_photoshop_elements_8.html
- http://retrogod.altervista.org/9sg_adobe_pe_local.html
- http://secunia.com/advisories/36895
- http://www.securityfocus.com/archive/1/506806/100/0/threaded
- http://www.securityfocus.com/bid/36542
- http://www.securitytracker.com/id?1022963
- http://www.vupen.com/english/advisories/2009/2798
- http://blogs.adobe.com/psirt/2009/09/potential_photoshop_elements_8.html
- http://retrogod.altervista.org/9sg_adobe_pe_local.html
- http://secunia.com/advisories/36895
- http://www.securityfocus.com/archive/1/506806/100/0/threaded
- http://www.securityfocus.com/bid/36542
- http://www.securitytracker.com/id?1022963
- http://www.vupen.com/english/advisories/2009/2798
→ the Explorer · watch your stack · NVD