Webroot Software Desktop Firewall Multiple Local Vulnerabilities
BID:15016
Info
Webroot Software Desktop Firewall Multiple Local Vulnerabilities
| Bugtraq ID: | 15016 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 06 2005 12:00AM |
| Updated: | Oct 06 2005 12:00AM |
| Credit: | Tan Chew Keong of Secunia Research is credited with the discovery of these issues. |
| Vulnerable: |
Webroot Software Desktop Firewall 1.3 .0.43 |
| Not Vulnerable: |
Webroot Software Desktop Firewall 1.3 .0.52 |
Discussion
Webroot Software Desktop Firewall Multiple Local Vulnerabilities
Webroot Software Desktop Firewall is susceptible to multiple local vulnerabilities.
The first issue is a buffer overflow vulnerability, due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.
Local attackers may exploit this first issue to execute arbitrary machine code with SYSTEM privileges. Attackers require the ability to modify the firewall's list of allowed applications.
The second issue is an authentication bypass vulnerability. This issue is due to a failure of the firewall to properly enforce built-in password protection, allowing local attackers to disable the firewall.
Local attackers may exploit the second issue to disable the firewall, aiding them in further attacks.
These issues may only be exploited by local attackers with privileges allowing them to utilize 'DeviceIoControl()' to send commands to the firewall driver.
These issues are reported to exist in version 1.3.0.43. Other versions may also be affected.
Webroot Software Desktop Firewall is susceptible to multiple local vulnerabilities.
The first issue is a buffer overflow vulnerability, due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.
Local attackers may exploit this first issue to execute arbitrary machine code with SYSTEM privileges. Attackers require the ability to modify the firewall's list of allowed applications.
The second issue is an authentication bypass vulnerability. This issue is due to a failure of the firewall to properly enforce built-in password protection, allowing local attackers to disable the firewall.
Local attackers may exploit the second issue to disable the firewall, aiding them in further attacks.
These issues may only be exploited by local attackers with privileges allowing them to utilize 'DeviceIoControl()' to send commands to the firewall driver.
These issues are reported to exist in version 1.3.0.43. Other versions may also be affected.
Exploit / POC
Webroot Software Desktop Firewall Multiple Local Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Webroot Software Desktop Firewall Multiple Local Vulnerabilities
Solution:
The vendor has released version 1.3.0.52 of the affected application, along with a knowledge base article to address these issues. The vendor recommends using the "Check for Updates Now" feature of the software to download the updated version.
Solution:
The vendor has released version 1.3.0.52 of the affected application, along with a knowledge base article to address these issues. The vendor recommends using the "Check for Updates Now" feature of the software to download the updated version.
References
Webroot Software Desktop Firewall Multiple Local Vulnerabilities
References:
References:
- Desktop Firewall Product Page (Webroot Software)
- Secunia Security Briefing Update (Webroot Software)