PT-2007-1232 · Computer Associates · Computer Associates Host Intrusion Prevention System (Hips) Drivers

Published

2007-01-24

·

Updated

2018-10-16

·

CVE-2006-6952

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Computer Associates Host Intrusion Prevention System (HIPS) drivers version 6.5.4.31 Computer Associates Host Intrusion Prevention System (HIPS) Firewall drivers version 6.5.4.10
Description: The issue allows local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers.
Recommendations: For version 6.5.4.31, restrict access to the kmxstart.sys driver to minimize the risk of exploitation. For version 6.5.4.10, consider disabling the kmxfw.sys driver until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6952

Affected Products

Computer Associates Host Intrusion Prevention System (Hips) Drivers