CVE-2009-4606
Estado: ModificadaAlta (7.2)—
South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.80%
- Percentil entre todas las CVEs puntuadas: 55
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://osvdb.org/59080
- http://retrogod.altervista.org/9sg_south_river_priv.html
- http://secunia.com/advisories/37083
- http://www.securityfocus.com/archive/1/507323/100/0/threaded
- http://www.vupen.com/english/advisories/2009/2994
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53885
- http://osvdb.org/59080
- http://retrogod.altervista.org/9sg_south_river_priv.html
- http://secunia.com/advisories/37083
- http://www.securityfocus.com/archive/1/507323/100/0/threaded
- http://www.vupen.com/english/advisories/2009/2994
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53885
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-4606",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-01-13T11:30:00.373",
"references": [
{
"url": "http://osvdb.org/59080",
"source": "cve@mitre.org"
},
{
"url": "http://retrogod.altervista.org/9sg_south_river_priv.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/37083",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/507323/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2009/2994",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53885",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/59080",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://retrogod.altervista.org/9sg_south_river_priv.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/37083",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/507323/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2009/2994",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53885",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command."
},
{
"lang": "es",
"value": "South River Technologies WebDrive v9.02 build 2232 instala el servicio de disco remoto sin un descriptor de seguridad, lo que permite a usuarios locales (1) parar el servicio a través del comando \"stop\", (2) ejecutar comandos arbitrarios como SYSTEM mediante el uso del comando \"config\" para modificar la variable \"binPatch\", o (3) reiniciar el servicio a través del comando \"Start\"."
}
],
"lastModified": "2026-06-16T23:14:00.663",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:south_river_technologies:webdrive:9.02:build_2232:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FAABF1E0-FCA2-4206-8C33-CF8ED8E7EBAF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}