PT-2008-6202 · Isecsoft · Isecsoft Anti-Trojan Elite
Published
2008-11-13
·
Updated
2017-08-08
·
CVE-2008-5048
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ISecSoft Anti-Trojan Elite versions 4.2.1 and earlier
Description
The issue is related to a buffer overflow in the Atepmon.sys driver, which can be triggered by local users sending long inputs to the "0x00222494" IOCTL. This can cause a denial of service, resulting in a system crash, and potentially allow the execution of arbitrary code.
Recommendations
For ISecSoft Anti-Trojan Elite versions 4.2.1 and earlier, consider updating to a newer version that addresses this issue, if available. As a temporary workaround, restrict access to the Atepmon.sys driver to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Isecsoft Anti-Trojan Elite