- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Check Point Zone Labs VSDATANT Multiple IOCTL Privilege Escalation
Vulnerabilities
------------------------------------------------------------------------
SUMMARY
<http://www.zonelabs.com/> Zone Alarm products "provide security
solutions such as anti-virus, firewall, spy-ware, and ad-ware protection.
The vsdatant.sys driver, also known as the TrueVector Device Driver, is
the core firewall driver in ZoneAlarm products".
Local exploitation of multiple input validation vulnerabilities within
multiple Check Point Zone Alarm products could allow an attacker to
execute arbitrary code in kernel (ring0) context.
DETAILS
Vulnerable Systems:
* Check Point Zone Labs Zone Alarm Free version 6.5.737.0 (vsdatant.sys).
* (All other products within the Zone Alarm product line are suspected to
be vulnerable).
* (Previous versions are also suspected to be vulnerable).
The problems specifically exist within the IOCTL handling code in the
vsdatant.sys device driver. The device driver fails to validate user-land
supplied addresses passed to IOCTL 0x8400000F and IOCTL 0x84000013.
Since the Irp parameters are not correctly validated, an attacker could
utilize these IOCTLs to overwrite arbitrary memory with the constant
double-word value of 0x60001 or the contents of a buffer returned from
ZwQuerySystemInformation. This includes kernel memory as well as the code
segments of running processes.
Exploitation allows an attacker to gain complete control of the affected
machine. The access control mechanisms under a default installation allow
restricted accounts to access the affected device drivers.
CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4216>
CVE-2007-4216
Disclosure Timeline:
* 12/19/2006 - Initial vendor notification
* 12/20/2006 - Initial vendor response
* 08/20/2007 - Coordinated public disclosure
ADDITIONAL INFORMATION
The information has been provided by iDefense.
The original article can be found at:
<http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=584>
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=584
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
No comments:
Post a Comment