PT-2009-4867 · Online Armor · Online Armor Personal Firewall

Published

2009-07-13

·

Updated

2017-09-19

·

CVE-2009-2450

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Online Armor Personal Firewall AV+ versions 3.1.0.0 through 3.5.0.11 Online Armor Personal Firewall versions 3.1.0.0 through 3.5.0.13
Description The issue allows local users to gain privileges via crafted METHOD NEITHER IOCTL requests to DeviceOAmon containing arbitrary kernel addresses. This can be demonstrated using the 0x830020C3 IOCTL.
Recommendations For Online Armor Personal Firewall AV+ versions 3.1.0.0 through 3.5.0.11, update to version 3.5.0.12 or later. For Online Armor Personal Firewall versions 3.1.0.0 through 3.5.0.13, update to version 3.5.0.14 or later.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2450

Affected Products

Online Armor Personal Firewall