PT-2010-5506 · Ca · Ca Internet Security Suite
Publicado
2010-12-08
·
Atualizado
2010-12-09
·
CVE-2010-4502
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CA Internet Security Suite Plus 2010 version 6.2.0.22
Description
The issue is caused by an integer overflow in the KmxSbx.sys driver, which allows local users to execute arbitrary code or cause a denial of service through pool corruption. This is achieved by passing crafted arguments to the "0x88000080" IOCTL, resulting in a buffer overflow.
Recommendations
For CA Internet Security Suite Plus 2010 version 6.2.0.22, consider disabling the KmxSbx.sys driver as a temporary workaround until a patch is available. Restrict access to the IOCTL "0x88000080" to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ca Internet Security Suite