>> Sony SunnComm MediaMax DRM Software Access Control Vulnerability
Title : Sony SunnComm MediaMax DRM Software Access Control Vulnerability VUPEN ID : VUPEN/ADV-2005-2783 CVE ID : CVE-2005-4069
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-12-07
Technical Description
A vulnerability has been identified in SunnComm MediaMax, which could be exploited by local attackers to obtain elevated privileges. This flaw is due to an access validation error in the "SunnComm Shared" directory granting "Full Control" privileges to "Everyone", which could be exploited by malicious users to overwrite and replace arbitrary programs (e.g. "MMX.EXE") with malicious files that will be automatically executed when a user inserts a Media Max protected CD.