Sony Music CD (SunnComm Media Max) Unsafe Permissions Let Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1015327
|
|
SecurityTracker URL: http://securitytracker.com/id?1015327
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Updated: Dec 11 2005
|
Original Entry Date: Dec 8 2005
|
Impact: Execution of arbitrary code via local system, User access via local system
|
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): Media Max version 5.0.21.0
|
Description: A vulnerability was reported in the SunnComm Media Max copy protection software used in certain Sony music CDs. A local user can obtain elevated privileges.
The copy protection software installs itself with unsafe permissions. The software creates the 'SunnComm Shared' directory and assigns
'Full Control' rights to the 'Everyone' group for that directory. As a result, a local user or a remote authenticated user can
modify or replace executable files in that directory. For example, the user replace the 'MMX.EXE' file with arbitrary code. Then,
when the target user plays an affected Sony music CD, the arbitrary code will be executed with the privileges of the target user.
Jesse
Burns and Alex Stamos of Information Security Partners discovered and reported this vulnerability.
The original advisory is available
at:
http://www.eff.org/IP/DRM/Sony-BMG/MediaMaxVulnerabilityReport.pdf
|
Impact: A local user can gain elevated privileges on the target system.
|
Solution: The vendor issued a fix [http://www.sunncomm.com/support/updates/updates.asp], however, the fix reportedly contains a vulnerability.
A local user can modify the MediaMax files to execute arbitrary code when the target user installs and runs the MediaMax patch.
The
vendor's advisory is available at:
http://www.sonybmg.com/indexmediamax.html
|
Vendor URL: www.sonybmg.com/indexmediamax.html (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 8 Dec 2005 00:18:56 -0500
Subject: Sony Music CD vulnerability
|
http://www.eff.org/IP/DRM/Sony-BMG/MediaMaxVulnerabilityReport.pdf
|
|