Centrino Intel PRO/Wireless Network Connection Drivers Remote Code Execution Vulnerability
BID:19864
Info
Centrino Intel PRO/Wireless Network Connection Drivers Remote Code Execution Vulnerability
| Bugtraq ID: | 19864 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2006 12:00AM |
| Updated: | Apr 18 2008 12:29AM |
| Credit: | johnycsh is credited with discovering this vulnerability. |
| Vulnerable: |
Intel PROSet/Wireless 10.1 .33 Intel PROSet/Wireless 9 Intel PROSet/Wireless 8 Intel PROSet/Wireless 10 Intel PRO/Wireless 2915ABG 9 Intel PRO/Wireless 2915ABG 10 Intel PRO/Wireless 2200BG 9 Intel PRO/Wireless 2200BG 8 Intel PRO/Wireless 2200BG 10 |
| Not Vulnerable: |
Intel PROSet/Wireless 10.5 |
Discussion
Centrino Intel PRO/Wireless Network Connection Drivers Remote Code Execution Vulnerability
Intel PRO/Wireless Network Connection drivers are prone to a remote code-execution vulnerability.
An attacker may trigger this vulnerability to corrupt memory and execute arbitrary code in the vulnerable system with kernel-level credentials.
A successful attack can result in a complete compromise of the affected computer.
Intel PRO/Wireless Network Connection drivers are prone to a remote code-execution vulnerability.
An attacker may trigger this vulnerability to corrupt memory and execute arbitrary code in the vulnerable system with kernel-level credentials.
A successful attack can result in a complete compromise of the affected computer.
Exploit / POC
Centrino Intel PRO/Wireless Network Connection Drivers Remote Code Execution Vulnerability
The discoverer of this issue has demonstrated that it can be exploited to crash an affected computer or overwrite EIP with attacker-specified data.
The following exploits are available:
The discoverer of this issue has demonstrated that it can be exploited to crash an affected computer or overwrite EIP with attacker-specified data.
The following exploits are available:
Solution / Fix
Centrino Intel PRO/Wireless Network Connection Drivers Remote Code Execution Vulnerability
Solution:
Intel has released an advisory along with fixes to address this issue. Please see the references for information on obtaining and applying fixes.
Solution:
Intel has released an advisory along with fixes to address this issue. Please see the references for information on obtaining and applying fixes.
References
Centrino Intel PRO/Wireless Network Connection Drivers Remote Code Execution Vulnerability
References:
References:
- [Dailydave] This guy cracks me up. (MindsX) (johnycsh)
- Intel PRO/Wireless Network Connection Product Page (Intel)
- Intel Wireless LAN Software & Drivers for Windows* (Intel)
- Vulnerability Note VU#524332 (US-CERT)
- INTEL-SA-00001: Intel® Centrino Wireless Driver Malformed Frame Remote Code Exec (Intel)