SecureOL VE2 Physical Memory Secured Environment Access Vulnerability
BID:14768
Info
SecureOL VE2 Physical Memory Secured Environment Access Vulnerability
| Bugtraq ID: | 14768 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 07 2005 12:00AM |
| Updated: | Sep 07 2005 12:00AM |
| Credit: | Discovery is credited to Joe Stewart. |
| Vulnerable: |
SecureOL VE2 |
| Not Vulnerable: |
SecureOL VE2 1.5.1009 |
Discussion
SecureOL VE2 Physical Memory Secured Environment Access Vulnerability
SecureOL VE2 can allow local attackers to gain unauthorized direct access to physical memory and the secured environment.
A successful attack can allow the attacker to gain access to the secured environment created by the application, which can lead to various attacks due to information disclosure.
SecureOL VE2 can allow local attackers to gain unauthorized direct access to physical memory and the secured environment.
A successful attack can allow the attacker to gain access to the secured environment created by the application, which can lead to various attacks due to information disclosure.
Exploit / POC
SecureOL VE2 Physical Memory Secured Environment Access Vulnerability
An exploit is not required.
A proof of concept example is available from the following Web site:
http://cybermessageboard.xeran.com/secureol/viewtopic.php?t=26
An exploit is not required.
A proof of concept example is available from the following Web site:
http://cybermessageboard.xeran.com/secureol/viewtopic.php?t=26
Solution / Fix
SecureOL VE2 Physical Memory Secured Environment Access Vulnerability
Solution:
Reportedly, VE2 version 1.05.1009 is not vulnerable to this issue. This has not been confirmed. Please contact the vendor for more information.
Solution:
Reportedly, VE2 version 1.05.1009 is not vulnerable to this issue. This has not been confirmed. Please contact the vendor for more information.
References
SecureOL VE2 Physical Memory Secured Environment Access Vulnerability
References:
References: