PT-2007-1232 · Computer Associates · Computer Associates Host Intrusion Prevention System (Hips) Drivers
Publicado
2007-01-24
·
Atualizado
2018-10-16
·
CVE-2006-6952
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Computer Associates Host Intrusion Prevention System (HIPS) drivers version 6.5.4.31
Computer Associates Host Intrusion Prevention System (HIPS) Firewall drivers version 6.5.4.10
Description:
The issue allows local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers.
Recommendations:
For version 6.5.4.31, restrict access to the kmxstart.sys driver to minimize the risk of exploitation.
For version 6.5.4.10, consider disabling the kmxfw.sys driver until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Computer Associates Host Intrusion Prevention System (Hips) Drivers