PT-2008-3038 · Panda · Panda Internet Security+1
Tobias Klein
·
Published
2008-03-24
·
Updated
2018-10-11
·
CVE-2008-1471
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Panda Internet Security versions 2008
Panda Antivirus+ Firewall versions 2008
Description
The issue allows local users to cause a denial of service, overwrite memory, or execute arbitrary code via a crafted IOCTL request. This request triggers an out-of-bounds write of kernel memory.
Recommendations
For Panda Internet Security version 2008, consider disabling the cpoint.sys driver as a temporary workaround until a patch is available.
For Panda Antivirus+ Firewall version 2008, restrict access to the cpoint.sys driver to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Panda Antivirus+ Firewall
Panda Internet Security