Sysinternals Regmon Local Denial of Service Vulnerability
BID:11042
Info
Sysinternals Regmon Local Denial of Service Vulnerability
| Bugtraq ID: | 11042 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 25 2004 12:00AM |
| Updated: | Aug 25 2004 12:00AM |
| Credit: | Discovery is credited to Next Generation Security Technologies. |
| Vulnerable: |
Sysinternals Regmon 6.11 |
| Not Vulnerable: | |
Discussion
Sysinternals Regmon Local Denial of Service Vulnerability
Regmon is reported prone to a local denial of service vulnerability. This issue presents itself because the application fails to handle exceptional conditions and references unvalidated pointers to kernel functions.
Successful exploitation may allow a local unauthorized attacker to cause a denial of service condition in the application. The attacker may then obfuscate changes to the registry from the administrator and carry out further attacks against a vulnerable computer.
Regmon 6.11 for NT/9x and prior versions are reportedly affected by this issue.
Regmon is reported prone to a local denial of service vulnerability. This issue presents itself because the application fails to handle exceptional conditions and references unvalidated pointers to kernel functions.
Successful exploitation may allow a local unauthorized attacker to cause a denial of service condition in the application. The attacker may then obfuscate changes to the registry from the administrator and carry out further attacks against a vulnerable computer.
Regmon 6.11 for NT/9x and prior versions are reportedly affected by this issue.
Exploit / POC
Sysinternals Regmon Local Denial of Service Vulnerability
A proof of concept exploit is available:
A proof of concept exploit is available:
Solution / Fix
Sysinternals Regmon Local Denial of Service Vulnerability
Solution:
It is reported that Regmon version 6.12 is not vulnerable to this issue. This version is not available at the moment.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that Regmon version 6.12 is not vulnerable to this issue. This version is not available at the moment.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sysinternals Regmon Local Denial of Service Vulnerability
References:
References:
- NtRegmon, local system denial of service (Next Generation Security Technologies)
- Regmon Product Page (Sysinternals)