The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2008-08-12 23:41
Updated : 2024-02-28 11:21
NVD link : CVE-2008-2926
Mitre link : CVE-2008-2926
CVE.ORG link : CVE-2008-2926
JSON object : View
Products Affected
ca
- personal_firewall_2008
- internet_security_suite_2008
- host_based_intrusion_prevention_system
- personal_firewall_2007
broadcom
- internet_security_suite
CWE
CWE-20
Improper Input Validation