PT-2010-5506 · Ca · Ca Internet Security Suite

Publicado

2010-12-08

·

Atualizado

2010-12-09

·

CVE-2010-4502

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CA Internet Security Suite Plus 2010 version 6.2.0.22
Description The issue is caused by an integer overflow in the KmxSbx.sys driver, which allows local users to execute arbitrary code or cause a denial of service through pool corruption. This is achieved by passing crafted arguments to the "0x88000080" IOCTL, resulting in a buffer overflow.
Recommendations For CA Internet Security Suite Plus 2010 version 6.2.0.22, consider disabling the KmxSbx.sys driver as a temporary workaround until a patch is available. Restrict access to the IOCTL "0x88000080" to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-4502

Produtos afetados

Ca Internet Security Suite