peter bassill · operator
$ cve CVE-2009-3489 JSON

CVE-2009-3489 EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS1.95% — more likely to be exploited than 80% of all CVEs
WeaknessCWE-732
On CISA KEVno
Public exploityes
Published2009-09-30
Last modified2026-06-16

Affected (1)

VendorProduct
adobephotoshop elements

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD