Overview
SunnComm MediaMax contains a privilege elevation vulnerability, which may allow a user with limited rights to execute code with elevated privileges.
Description
SunnComm MediaMax SunnComm MediaMax is copy protection software that is automatically installed by some audio CDs. Sony BMG has provided a list of titles that include MediaMax version 5 software. A device driver is Included with the MediaMax software, which prevents the CD from being copied. The user must be a member of the Windows "Administrators" or "Power Users" group for the software to install. Note that the driver and part of the software is installed before the End User License Agreement (EULA) is presented to the user. |
Impact
This vulnerability may give a user with access to the filesystem the ability to execute arbitrary code with elevated privileges. |
Solution
Apply a patch or update |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.sunncomm.com/support/faq/
- http://www.sonybmg.com/mediamax/titles.html
- http://www.eff.org/IP/DRM/Sony-BMG/MediaMaxVulnerabilityReport.pdf
- http://www.eff.org/news/archives/2005_12.php#004234
- http://www.securityfocus.com/bid/15754
- http://securitytracker.com/id?1015327
- http://secunia.com/advisories/17933
Acknowledgements
Thanks to EFF for reporting this vulnerability, who in turn credit Jesse Burns and Alex Stamos of iSEC Partners.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2005-4069 |
Severity Metric: | 2.81 |
Date Public: | 2005-12-06 |
Date First Published: | 2006-04-12 |
Date Last Updated: | 2006-04-12 19:57 UTC |
Document Revision: | 7 |