← Vulnerability feed

Vulnerability record · CVE-2005-4708 · published 31 December 2005

CVE-2005-4708: Adobe captivate vulnerability

Adobe · Captivate

Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.

7.2 CVSS 2.0 High EPSS 1.2% · top 32.5%
7.2CVSS 2.0 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/15654
http://securitytracker.com/id?1014158
http://securitytracker.com/id?1014159
http://securitytracker.com/id?1014160
http://securitytracker.com/id?1014161
http://securitytracker.com/id?1014162
http://securitytracker.com/id?1014163
http://securitytracker.com/id?1014164
http://securitytracker.com/id?1014165
http://securitytracker.com/id?1014166
http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf
http://www.kb.cert.org/vuls/id/953860 US Government Resource
http://www.macromedia.com/devnet/security/security_zone/mpsb05-04.html PatchVendor Advisory
http://www.osvdb.org/17248
http://www.securityfocus.com/archive/1/423587/100/0/threaded
http://www.securityfocus.com/bid/13925
http://www.vupen.com/english/advisories/2005/0723
http://secunia.com/advisories/15654
http://securitytracker.com/id?1014158
http://securitytracker.com/id?1014159
http://securitytracker.com/id?1014160
http://securitytracker.com/id?1014161
http://securitytracker.com/id?1014162
http://securitytracker.com/id?1014163
http://securitytracker.com/id?1014164
http://securitytracker.com/id?1014165
http://securitytracker.com/id?1014166
http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf
http://www.kb.cert.org/vuls/id/953860 US Government Resource
http://www.macromedia.com/devnet/security/security_zone/mpsb05-04.html PatchVendor Advisory
http://www.osvdb.org/17248
http://www.securityfocus.com/archive/1/423587/100/0/threaded
http://www.securityfocus.com/bid/13925
http://www.vupen.com/english/advisories/2005/0723

Track CVE-2005-4708 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-4924Adobe dreamweaver os command injection vulnerabilityAdobe Dreamweaver CC versions 18.0 and earlier have an OS Command Injection vulnerability. Successful exploitation could lead to arbitrary code execu…EPSS 14%9.8CVE-2017-3098Adobe captivate improper input validation vulnerabilityAdobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and writ…EPSS 6.9%9.3CVE-2010-3191Adobe captivate vulnerabilityUntrusted search path vulnerability in Adobe Captivate 5.0.0.596, and possibly other versions, allows local users, and possibly remote attackers, to …EPSS 5.7%9.3CVE-2010-3132Adobe dreamweaver vulnerabilityUntrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, allows local users, and possib…EPSS 14%9.3CVE-2010-0128Adobe director out-of-bounds write vulnerabilityInteger signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to ca…EPSS 5.0%8.6CVE-2026-47906Adobe dreamweaver vulnerabilityDreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arb…EPSS 0.29%8.6CVE-2026-47907Adobe dreamweaver improper access control vulnerabilityDreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution …EPSS 0.28%8.6CVE-2026-21267Adobe dreamweaver os command injection vulnerabilityDreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec…EPSS 0.83%

Source: NIST National Vulnerability Database (record CVE-2005-4708), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.