PT-2012-1369 · Comodo · Comodo Internet Security

Publicado

2012-08-25

·

Atualizado

2012-08-27

·

CVE-2010-5157

CVSS v2.0

6.2

Média

VetorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Comodo Internet Security versions prior to 4.1.149672.916
Description A race condition exists that allows local users to bypass kernel-mode hook handlers and execute dangerous code. This is achieved through certain user-space memory changes during hook-handler execution. The issue can be exploited via an argument-switch attack or a KHOBE attack, which would otherwise be blocked by a handler but not by signature-based malware detection.
Recommendations For Comodo Internet Security versions prior to 4.1.149672.916, update to version 4.1.149672.916 or later to resolve the issue.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-5157

Produtos afetados

Comodo Internet Security