Cisco Security Agent for Microsoft Windows SMB Remote Buffer Overflow Vulnerability
BID:26723
Info
Cisco Security Agent for Microsoft Windows SMB Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 26723 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-5580 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2007 12:00AM |
| Updated: | Dec 06 2007 09:12PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Cisco Security Agent 5.1 .79 Cisco Security Agent 5.0 .193 Cisco Security Agent 4.5.1 .657 Cisco Security Agent 4.5.1 .639 Cisco Security Agent 4.5.1 Cisco Security Agent 4.5 Cisco Security Agent 4.0.3 .728 Cisco Security Agent 4.0.3 Cisco Security Agent 4.0.2 Cisco Security Agent 4.0.1 Cisco Security Agent 4.0 Cisco Security Agent 2.1 Cisco Security Agent 5.2 Cisco Security Agent 5.1 Cisco Security Agent 5.0.0.201 Cisco Security Agent 5.0 Cisco Security Agent 4.5.1.659 Cisco Security Agent 4.5.1.659 Cisco Security Agent 3.x |
| Not Vulnerable: | |
Discussion
Cisco Security Agent for Microsoft Windows SMB Remote Buffer Overflow Vulnerability
Cisco Security Agent for Microsoft Windows is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data.
Remote attackers can exploit this issue to execute arbitrary machine code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed attacks will likely cause denial-of-service conditions.
This issue affects all standalone and managed versions of Cisco Security Agent for Windows.
Cisco Security Agent for Microsoft Windows is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data.
Remote attackers can exploit this issue to execute arbitrary machine code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed attacks will likely cause denial-of-service conditions.
This issue affects all standalone and managed versions of Cisco Security Agent for Windows.
Exploit / POC
Cisco Security Agent for Microsoft Windows SMB Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco Security Agent for Microsoft Windows SMB Remote Buffer Overflow Vulnerability
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for information on how to obtain and apply the fixes.
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for information on how to obtain and apply the fixes.
References
Cisco Security Agent for Microsoft Windows SMB Remote Buffer Overflow Vulnerability
References:
References:
- Cisco Security Agent Homepage (Cisco)
- Cisco Security Advisory: Cisco Security Agent for Windows System Driver Remote B (Cisco Systems Product Security Incident Response Team
) - NSFOCUS SA2007-02 : Cisco Security Agent Remote Buffer Overflow Vulnerability (NSFOCUS Security Team
) - Cisco Security Advisory: Cisco Security Agent for Windows System Driver Remote B (Cisco)