Compuware DriverStudio Remote Control Null Session Authentication Bypass Vulnerability
BID:14837
Info
Compuware DriverStudio Remote Control Null Session Authentication Bypass Vulnerability
| Bugtraq ID: | 14837 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2005 12:00AM |
| Updated: | Sep 15 2005 12:00AM |
| Credit: | Discovery is credited to cocoruder. |
| Vulnerable: |
Compuware DriverStudio 3.0 beta 2 Compuware DriverStudio 2.7 |
| Not Vulnerable: | |
Discussion
Compuware DriverStudio Remote Control Null Session Authentication Bypass Vulnerability
Compuware DriverStudio is prone to an issue that may permit remote attackers to bypass authentication. This issue exists in the DriverStudio Remote Control Service.
If the attack is successful, it is possible to launch further attacks that could result in execution of arbitrary code on the vulnerable computer.
Compuware DriverStudio is prone to an issue that may permit remote attackers to bypass authentication. This issue exists in the DriverStudio Remote Control Service.
If the attack is successful, it is possible to launch further attacks that could result in execution of arbitrary code on the vulnerable computer.
Exploit / POC
Compuware DriverStudio Remote Control Null Session Authentication Bypass Vulnerability
The discoverer of this issue has reportedly developing working exploit code. This exploit code is not publicly available and is not known to be circulating in the wild.
The discoverer of this issue has reportedly developing working exploit code. This exploit code is not publicly available and is not known to be circulating in the wild.
Solution / Fix
Compuware DriverStudio Remote Control Null Session Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Compuware DriverStudio Remote Control Null Session Authentication Bypass Vulnerability
References:
References: