PT-2007-1232 · Computer Associates · Computer Associates Host Intrusion Prevention System (Hips) Drivers
Published
2007-01-24
·
Updated
2018-10-16
·
CVE-2006-6952
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Computer Associates Host Intrusion Prevention System (HIPS) drivers version 6.5.4.31
Computer Associates Host Intrusion Prevention System (HIPS) Firewall drivers version 6.5.4.10
Description:
The issue allows local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers.
Recommendations:
For version 6.5.4.31, restrict access to the kmxstart.sys driver to minimize the risk of exploitation.
For version 6.5.4.10, consider disabling the kmxfw.sys driver until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Computer Associates Host Intrusion Prevention System (Hips) Drivers