vendor:
CA Internet Security Suite 2010
by:
Nikita Tarakanov
7.5
CVSS
HIGH
Pool Corruption
CWE
Product Name: CA Internet Security Suite 2010
Affected Version From: Up to date, KmxSbx.sys version 6.2.0.22
Affected Version To: Up to date, KmxSbx.sys version 6.2.0.22
Patch Exists: No
Related CWE: CVE-NO-MATCH
CPE:
Platforms Tested: Windows XP SP3
2010
CA Internet Security Suite 2010 KmxSbx.sys Kernel Pool Overflow 0-day Exploit
The KmxSbx.sys kernel driver in CA Internet Security Suite 2010 is vulnerable to a pool corruption vulnerability in the handling of IOCTL 0x88000080. This allows an attacker with local access to execute arbitrary code within the kernel.
Mitigation:
No known mitigation