PT-2010-5506 · Ca · Ca Internet Security Suite

Published

2010-12-08

·

Updated

2010-12-09

·

CVE-2010-4502

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CA Internet Security Suite Plus 2010 version 6.2.0.22
Description The issue is caused by an integer overflow in the KmxSbx.sys driver, which allows local users to execute arbitrary code or cause a denial of service through pool corruption. This is achieved by passing crafted arguments to the "0x88000080" IOCTL, resulting in a buffer overflow.
Recommendations For CA Internet Security Suite Plus 2010 version 6.2.0.22, consider disabling the KmxSbx.sys driver as a temporary workaround until a patch is available. Restrict access to the IOCTL "0x88000080" to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4502

Affected Products

Ca Internet Security Suite