full-disclosure-uk: [Full-disclosure] [TKADV2008-006] CA HIPS Km
[Full-disclosure] [TKADV2008-006] CA HIPS KmxFw.sys Kernel Memory Corruption
From: Tobias Klein <tk_at_nospam>
Date: Tue Aug 12 2008 - 19:44:41 GMT To: bugtraq@securityfocus.com
The kernel driver KmxFw.sys shipped with various CA products contains a
vulnerability in the code that handles IOCTL requests. Exploitation of
this vulnerability can result in:
local denial of service attacks (system crash due to a kernel panic),
or
local execution of arbitrary code at the kernel level (complete
system compromise)