Lucene search

K
cve[email protected]CVE-2008-2926
HistoryAug 12, 2008 - 11:41 p.m.

CVE-2008-2926

2008-08-1223:41:00
CWE-20
web.nvd.nist.gov
19
security
vulnerability
kmxfw.sys
ca
hips
denial of service
privilege escalation
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.6%

The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request.

Affected configurations

NVD
Node
broadcominternet_security_suiteMatch3.0
OR
cahost_based_intrusion_prevention_systemMatchr8
OR
cainternet_security_suite_2008
OR
capersonal_firewall_2007
OR
capersonal_firewall_2008

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.6%