BitDefender Antivirus 2008 Hooked SSDT Denial of Service Vulnerability
BID:28741
Info
BitDefender Antivirus 2008 Hooked SSDT Denial of Service Vulnerability
| Bugtraq ID: | 28741 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1735 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 28 2008 12:00AM |
| Updated: | May 05 2008 10:45PM |
| Credit: | Damian Saura, Anibal Sacco, Daro Menichelli, Norberto Kueffner, Andrs Blanco y Rodrigo Carvalho from Core Security Technologies |
| Vulnerable: |
BitDefender Antivirus 2008 0 |
| Not Vulnerable: | |
Discussion
BitDefender Antivirus 2008 Hooked SSDT Denial of Service Vulnerability
BitDefender Antivirus 2008 is prone to a local denial-of-service vulnerability because it fails to adequately bounds-check user-supplied data.
Exploiting this vulnerability allows local attackers to crash affected computers, denying service to legitimate users. Attackers might also be able to gain elevated privileges by executing arbitrary machine code in the context of the kernel, but this has not been confirmed.
BitDefender Antivirus 2008 Build 11.0.11 is vulnerable; other versions may also be affected.
BitDefender Antivirus 2008 is prone to a local denial-of-service vulnerability because it fails to adequately bounds-check user-supplied data.
Exploiting this vulnerability allows local attackers to crash affected computers, denying service to legitimate users. Attackers might also be able to gain elevated privileges by executing arbitrary machine code in the context of the kernel, but this has not been confirmed.
BitDefender Antivirus 2008 Build 11.0.11 is vulnerable; other versions may also be affected.
Exploit / POC
BitDefender Antivirus 2008 Hooked SSDT Denial of Service Vulnerability
Attackers can use 'BSODhook' from Matousec to exploit this issue.
Attackers can use 'BSODhook' from Matousec to exploit this issue.
Solution / Fix
BitDefender Antivirus 2008 Hooked SSDT Denial of Service Vulnerability
Solution:
The vendor released a patch to address this issue. The patch is available through the automatic update feature. Please see the references for more information.
Solution:
The vendor released a patch to address this issue. The patch is available through the automatic update feature. Please see the references for more information.
References
BitDefender Antivirus 2008 Hooked SSDT Denial of Service Vulnerability
References:
References:
- BitDefender Homepage (BitDefender)
- Security vulnerability in BitDefender 2008 (BitDefender)
- Insufficient argument validation of hooked SSDT functions on multiple Antivirus (Core Security Technologies)