ESET Smart Security 'epfw.sys' Local Privilege Escalation Vulnerability
BID:32917
Info
ESET Smart Security 'epfw.sys' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 32917 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5724 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 18 2008 12:00AM |
| Updated: | Dec 31 2008 08:31PM |
| Credit: | NT Internals |
| Vulnerable: |
Eset Smart Security 3.0.672 .0 Eset Smart Security 3.0.667 .0 Eset Smart Security 0 |
| Not Vulnerable: |
Eset Smart Security 3.0.684 .0 |
Discussion
ESET Smart Security 'epfw.sys' Local Privilege Escalation Vulnerability
ESET Smart Security is prone to a local privilege-escalation vulnerability that occurs in the 'easdrv.sys' driver.
An attacker can exploit this issue to execute arbitrary code with kernel-level privileges on a Microsoft Windows host operating system. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.
ESET Smart Security 3.0.672 and prior are vulnerable.
ESET Smart Security is prone to a local privilege-escalation vulnerability that occurs in the 'easdrv.sys' driver.
An attacker can exploit this issue to execute arbitrary code with kernel-level privileges on a Microsoft Windows host operating system. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.
ESET Smart Security 3.0.672 and prior are vulnerable.
Exploit / POC
ESET Smart Security 'epfw.sys' Local Privilege Escalation Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
ESET Smart Security 'epfw.sys' Local Privilege Escalation Vulnerability
Solution:
Vendor updates are available. Contact the vendor for details.
Solution:
Vendor updates are available. Contact the vendor for details.
References
ESET Smart Security 'epfw.sys' Local Privilege Escalation Vulnerability
References:
References:
- Changelog for ESET Smart Security and NOD32 3.0 (Eset Software)
- ESET Smart Security (epfw.sys) Privilege Escalation Vulnerability (NT Internals)
- ESET Smart Security Homepage (ESET)
- ESET Software Homepage (ESET Software)