Novell Client for Windows NWFILTER.SYS Local Privilege Escalation Vulnerability
BID:26420
Info
Novell Client for Windows NWFILTER.SYS Local Privilege Escalation Vulnerability
| Bugtraq ID: | 26420 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5667 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 13 2007 12:00AM |
| Updated: | Mar 13 2008 03:11AM |
| Credit: | Stephen Fewer of Harmony Security discovered this issue. |
| Vulnerable: |
Novell Client 4.91 SP4 Novell Client 4.91 SP3 Novell Client 4.91 SP2 Novell Client 4.91 SP1a Novell Client 4.91 SP1 Novell Client 4.91 |
| Not Vulnerable: | |
Discussion
Novell Client for Windows NWFILTER.SYS Local Privilege Escalation Vulnerability
Novell Client for Windows is prone to a local privilege-escalation vulnerability because it fails to adequately handle user-supplied input.
Authenticated attackers with the privileges to invoke executables can exploit this issue to execute arbitrary code with kernel-level privileges.
Novell Client for Windows 4.91 is vulnerable; other versions may also be affected.
Novell Client for Windows is prone to a local privilege-escalation vulnerability because it fails to adequately handle user-supplied input.
Authenticated attackers with the privileges to invoke executables can exploit this issue to execute arbitrary code with kernel-level privileges.
Novell Client for Windows 4.91 is vulnerable; other versions may also be affected.
Exploit / POC
Novell Client for Windows NWFILTER.SYS Local Privilege Escalation Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Novell Client for Windows NWFILTER.SYS Local Privilege Escalation Vulnerability
Solution:
Novell released an advisory and updates to address this issue. Please see the references for more information.
Novell Client 4.91 SP1a
Novell Client 4.91 SP1
Novell Client 4.91 SP4
Novell Client 4.91
Novell Client 4.91 SP3
Novell Client 4.91 SP2
Solution:
Novell released an advisory and updates to address this issue. Please see the references for more information.
Novell Client 4.91 SP1a
-
Novell 491presp3_nwfilter.zip
http://download.novell.com/Download?buildid=39EK-iJi0SE~
Novell Client 4.91 SP1
-
Novell 491presp3_nwfilter.zip
http://download.novell.com/Download?buildid=39EK-iJi0SE~
Novell Client 4.91 SP4
-
Novell 491psp4_nwfilter.zip
http://download.novell.com/Download?buildid=VXY3WAWrOYY~
Novell Client 4.91
-
Novell 491presp3_nwfilter.zip
http://download.novell.com/Download?buildid=39EK-iJi0SE~
Novell Client 4.91 SP3
-
Novell 491psp3_nwfilter.zip
http://download.novell.com/Download?buildid=vnrthLgZIE0~
Novell Client 4.91 SP2
-
Novell 491presp3_nwfilter.zip
http://download.novell.com/Download?buildid=39EK-iJi0SE~
References
Novell Client for Windows NWFILTER.SYS Local Privilege Escalation Vulnerability
References:
References: