---
cve: "CVE-2009-2564"
severity: "LOW"
cvss: 3.1
epss: "5.6%"
vendor: "n/a"
kev: false
exploited: false
published: "2009-07-21 17:30:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-14T11:27:49+02:00"
---

# CVE-2009-2564

> 3.1 LOW · 🧪 PoC

## Beschreibung

NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is limited because the program is deleted and the associated service is not automatically launched after a successful installation and reboot.

## Exploit-Evidenz

- [EDB-9223 — Adobe Acrobat 9.1.2 NOS - Local Privilege Escalation](https://www.exploit-db.com/exploits/9223) ✅
- [EDB-9199 — Adobe 9.x Related Service - 'getPlus_HelperSvc.exe' Local Privilege Escalation](https://www.exploit-db.com/exploits/9199) ✅

## Referenzen

- <http://www.exploit-db.com/exploits/9199>
- <http://www.us-cert.gov/cas/techalerts/TA09-286B.html>
- <http://securitytracker.com/id?1023007>
- <http://www.adobe.com/support/security/bulletins/apsb09-15.html>
- <https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5719>
- <http://www.securityfocus.com/bid/35740>
- <http://www.vupen.com/english/advisories/2009/1969>
- <http://retrogod.altervista.org/9sg_adobe_local.html>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/54383>
- <http://secunia.com/advisories/35930>
- <http://www.securityfocus.com/archive/1/505095/100/0/threaded>
- <http://www.vupen.com/english/advisories/2009/2898>
- <http://secunia.com/advisories/36331>
- <http://blogs.adobe.com/psirt/2009/07/local_privilege_escalation_in.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2009-2564) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
