CVE-2009-0311
EMC AutoStart Backbone Engine Trusted Pointer Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.
El servicio Backbone (ftbackbone.exe) en EMC AutoStart en versiones anteriores a 5.3 SP2, permite a los atacantes remotos ejecutar arbitrariamente código a través de un paquete con un valor manipulado que está desreferenciado como puntero a una función.
This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of EMC AutoStart. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the Backbone service (ftbackbone.exe) which listens by default on TCP port 8042. The process trusts a DWORD value from incoming packets which it arbitrarily calls. Exploitation of this issue leads to code execution under the context of the SYSTEM user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-01-23 CVE Published
- 2009-01-27 CVE Reserved
- 2024-03-18 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://osvdb.org/51566 | Vdb Entry | |
http://www.securityfocus.com/archive/1/500350/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/33415 | Vdb Entry | |
http://www.securitytracker.com/id?1021636 | Vdb Entry | |
http://zerodayinitiative.com/advisories/ZDI-09-009 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/48197 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/33667 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Autostart Search vendor "Emc" for product "Autostart" | <= 5.3 Search vendor "Emc" for product "Autostart" and version " <= 5.3" | sp1 |
Affected
| ||||||
Emc Search vendor "Emc" | Autostart Search vendor "Emc" for product "Autostart" | 5.3 Search vendor "Emc" for product "Autostart" and version "5.3" | - |
Affected
|