Just when you thought it was OK to play Music from your PC….
BetaNews | Oops — New Sony DRM Patch Insecure
Oops — New Sony DRM Patch Insecure
By Nate Mook, BetaNews
December 8, 2005, 11:40 AMJust one day after jointly announcing a patch to correct a security flaw in the SunnComm MediaMax copy protection included on 27 CDs, Sony BMG and the Electronic Frontier Foundation are urging users not to install it. The update includes a vulnerability similar to the one it attempted to fix.
SunnComm’s MediaMax version 5 software does not properly protect a directory it installs, opening the door for a privilege escalation attack. Thus, a restricted user account could replace the executables within the MediaMax directory with malicious code, which would then be executed by an administrator upon inserting a CD.









