Secunia - Stay Secure
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Symantec produkter IOCTL-handler rettighedseskalering Advisory Available in English 

Secunia Advisory: SA22288  
Udsendt: 2006-10-06
Sidste Opdt.: 2006-10-11

Kritisk:
Mindre kritisk
Betydning: Rettighedseskalering
Hvor: Lokalt System
Løsning Status: Producent Patch

Software:Symantec AntiVirus Corporate Edition 10.x
Symantec AntiVirus Corporate Edition 8.x
Symantec AntiVirus Corporate Edition 9.x
Symantec AntiVirus for Blue Coat Security
Symantec AntiVirus for CacheFlow Security Gateway
Symantec AntiVirus for Clearswift 4.x
Symantec AntiVirus for Inktomi Traffic Edge
Symantec AntiVirus for Microsoft ISA Server 4.x
Symantec AntiVirus for Microsoft SharePoint 4.x
Symantec AntiVirus for NetApp Filer/NetCache
Symantec AntiVirus Scan Engine 4.x
Symantec Brightmail AntiSpam 4.x
Symantec Brightmail AntiSpam 5.x
Symantec Brightmail AntiSpam 6.x
Symantec Client Security 1.x
Symantec Client Security 2.x
Symantec Client Security 3.x
Symantec Mail Security for Domino 4.x
Symantec Mail Security for Domino 5.x
Symantec Mail Security for Exchange 4.x
Symantec Mail Security for Microsoft Exchange 5.x
Symantec Mail Security for SMTP 4.x
Symantec Norton AntiVirus 2001
Symantec Norton AntiVirus 2002
Symantec Norton AntiVirus 2003
Symantec Norton AntiVirus 2004
Symantec Norton AntiVirus 2005
Symantec Norton AntiVirus 2006
Symantec Norton AntiVirus Corporate Edition 7.x
Symantec Norton Internet Security 2001
Symantec Norton Internet Security 2002
Symantec Norton Internet Security 2003
Symantec Norton Internet Security 2003 Professional
Symantec Norton Internet Security 2004
Symantec Norton Internet Security 2004 Professional
Symantec Norton Internet Security 2005
Symantec Norton Internet Security 2006
Symantec Norton SystemWorks 2001
Symantec Norton SystemWorks 2002
Symantec Norton SystemWorks 2003
Symantec Norton SystemWorks 2004
Symantec Norton SystemWorks 2005
Symantec Norton SystemWorks 2006
Symantec Web Security 2.x
Symantec Web Security 3.x

CVE reference:CVE-2006-4927 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Beskrivelse:
Der er rapporteret en sårbarhed i diverse Symantec produkter, som kan udnyttes af ondsindede, lokale brugere til at opnå eskalerede rettigheder.

Sårbarheden skyldes utilstrækkelig verificering af adresserum i IOCTL-handlerne i NAVEX15.SYS og NAVENG.SYS enhedsdriverne, hvilket gør det muligt at overskrive vilkårlig hukommelse med en konstant DWORD værdi. Dette kan udnyttes til at eksekvere vilkårlig kode med kerne-rettigheder ved at sende specielt udformede I/O Request pakker til 0x222AD3, 0x222AD7 og 0x222ADB IOCTL-handlerne.

Sårbarhederne er rapporteret i alle versioner af følgende produkter for Windows NT, Windows 2000 og Windows XP:
- Norton AntiVirus
- Norton Internet Security
- Norton System Works
- Symantec AntiVirus Corporate Edition
- Symantec AntiVirus for Blue Coat Security
- Symantec AntiVirus for CacheFlow Security Gateway
- Symantec AntiVirus for Clearswift MIME Sweeper
- Symantec AntiVirus for Inktomi Traffic Edge
- Symantec AntiVirus for Microsoft ISA Server
- Symantec AntiVirus for NetApp Filer/NetCache
- Symantec BrightMail AntiSpam
- Symantec Client Security
- Symantec Mail Security for Domino
- Symantec Mail Security for Exchange
- Symantec Mail Security for SMTP
- Symantec Scan Engine
- Symantec Web Security for Windows

Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.

Løsning:
Opdater til virus-definitionerne fra 04-10-2006 revision 9 eller nyere.

Rapporteret af / Kredit:
Rubén Santamarta, reversemode.com.

Forløb:
11-10-2006: Tilføjede link til US-CERT.

Original Advisory:
Symantec:
http://securityresponse.symantec.com/avcenter/security/Content/2006.10.05a.html

iDEFENSE:
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=417

Andre Kilder:
US-CERT VU#946820:
http://www.kb.cert.org/vuls/id/946820



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

52 Relaterede Secunia Advisories, displaying 10

1. Symantec Mail Security Lotus 1-2-3 fil-fortolkning buffer overflows
2. Symantec Mail Security for Exchange fil-fortolkining sårbarheder
3. Symantec Mail Security for SMTP filvisere buffer overflows
4. Symantec produkter real-time scanner notificeringsvindue rettighedseskalering
5. Symantec produkter CAB- og RAR-arkivhåndtering sårbarheder
6. Symantec produkter SYMTDI.SYS IOCTL-handler rettighedseskalering
7. Symantec produkter "Internet Email Auto-Protect" Denial of Service
8. Symantec Reporting Server tre sårbarheder
9. Norton Personal Firewall ISAlertDataCOM ActiveX-kontrol buffer overflow
10. Symantec produkter NavComUI ActiveX-kontrol kode-eksekvering

Vis alle relaterede advisories


Send Feedback to Secunia

Hvis du har ny information angående dette Secunia advisory eller et produkt i vores database, så send det venligst til os. Du kan sende det til os enten ved at bruge vores web formular eller ved at sende det til vuln@secunia.com.

Ideer, foreslag og andet feedback er også meget velkommen.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
Xoops PopnupBlog Module "index.php" Cross-Site Scripting
2.
IBM DB2 CLR Stored Procedures Unspecified Vulnerability
3.
DriveCrypt Plus Pack Password Disclosure Security Issue
4.
Sharity Unspecified Vulnerability
5.
IBM Lotus Quickr Multiple Cross-Site Scripting Vulnerabilities
6.
Sun Solaris NFS RPC Zones Denial of Service
7.
Smart Survey "sid" Cross-Site Scripting Vulnerability
8.
HP Enterprise Discovery Unspecified Privilege Escalation
9.
K-Rate Premium Multiple Vulnerabilities
10.
Red Hat update for kernel





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia