PT-2008-5009 · Microsoft+2 · Windows+2
Ruben Santamarta
·
Published
2008-09-10
·
Updated
2018-10-11
·
CVE-2008-3636
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
GEARAspiWDM.sys version 2.0.7.5 and earlier, as used in Apple iTunes before 8.0 and other products
Description
The issue is caused by an integer overflow in the IopfCompleteRequest API in the kernel, allowing context-dependent attackers to gain privileges. This can be exploited locally via repeated IoAttachDevice IOCTL calls to the
.GEARAspiWDMDevice in the GEARAspiWDM.sys driver. The estimated number of potentially affected devices and details about real-world incidents are not provided.Recommendations
For Microsoft Windows, update to a version that includes the fix for the integer overflow in the IopfCompleteRequest API.
For GEARAspiWDM.sys version 2.0.7.5 and earlier, consider disabling the
IoAttachDevice IOCTL call to .GEARAspiWDMDevice until a patch is available.
For Apple iTunes before 8.0, update to version 8.0 or later to mitigate the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gearaspiwdm.Sys
Windows
Itunes