PT-2008-5685 · Eset · Sysinspector Antistealth Driver+1

Alex

·

Publicado

2008-10-06

·

Atualizado

2017-09-29

·

CVE-2008-4451

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: ESET System Analyzer Tool version 1.1.1.0
Description: The issue allows local users to execute arbitrary code via a certain METHOD NEITHER IOCTL request to Deviceesiasdrv that overwrites a pointer in the SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0.
Recommendations: For ESET System Analyzer Tool version 1.1.1.0, consider restricting access to the Deviceesiasdrv device to minimize the risk of exploitation until a patch is available.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4451

Produtos afetados

Eset System Analyzer Tool
Sysinspector Antistealth Driver