Multiple SlySoft Products Driver IOCTL Request Multiple Local Buffer Overflow Vulnerabilities
BID:34103
Info
Multiple SlySoft Products Driver IOCTL Request Multiple Local Buffer Overflow Vulnerabilities
| Bugtraq ID: | 34103 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0824 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 12 2009 12:00AM |
| Updated: | May 26 2009 07:00PM |
| Credit: | Nikita Tarakanov of the Positive Technologies Research Team and NT Internals |
| Vulnerable: |
SlySoft Virtual CloneDrive 5.4.2 .3 SlySoft CloneDVD 2.9.2 .0 SlySoft CloneCD 5.3.1 .3 SlySoft AnyDVD HD 6.5.2.2 SlySoft AnyDVD 6.5.2.2 |
| Not Vulnerable: |
SlySoft Virtual CloneDrive 5.4.2 .5 SlySoft CloneDVD 2.9.2 .2 SlySoft CloneCD 5.3.1 .4 SlySoft AnyDVD HD 6.5.2.6 SlySoft AnyDVD 6.5.2.6 |
Discussion
Multiple SlySoft Products Driver IOCTL Request Multiple Local Buffer Overflow Vulnerabilities
Multiple SlySoft products are prone to multiple buffer-overflow vulnerabilities because they fail to adequately validate user-supplied input.
A local attacker can exploit these issues to execute arbitrary code with SYSTEM-level privileges. Failed attacks will result in denial-of-service conditions.
The following applications are vulnerable:
SlySoft AnyDVD 6.5.2.2
SlySoft AnyDVD HD 6.5.2.2
SlySoft Virtual CloneDrive 5.4.2.3
SlySoft CloneDVD 2.9.2.0
SlySoft CloneCD 5.3.1.3
Multiple SlySoft products are prone to multiple buffer-overflow vulnerabilities because they fail to adequately validate user-supplied input.
A local attacker can exploit these issues to execute arbitrary code with SYSTEM-level privileges. Failed attacks will result in denial-of-service conditions.
The following applications are vulnerable:
SlySoft AnyDVD 6.5.2.2
SlySoft AnyDVD HD 6.5.2.2
SlySoft Virtual CloneDrive 5.4.2.3
SlySoft CloneDVD 2.9.2.0
SlySoft CloneCD 5.3.1.3
Exploit / POC
Multiple SlySoft Products Driver IOCTL Request Multiple Local Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Multiple SlySoft Products Driver IOCTL Request Multiple Local Buffer Overflow Vulnerabilities
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
Multiple SlySoft Products Driver IOCTL Request Multiple Local Buffer Overflow Vulnerabilities
References:
References:
- AnyDVD Changelog (SlySoft)
- CloneCD Changelog (SlySoft)
- CloneDVD Changelog (SlySoft)
- NT Internals - Advisory NTIADV0812 - CloneCD/CloneDVD/Virtual CloneDrive/AnyDVD (NT Internals)
- PT-2009-11: SlySoft Multiple Products ElbyCDIO.sys Denial of Service (Positive Technologies)
- SlySoft Homepage (SlySoft)
- Virtual CloneDrive Changelog (SlySoft)
- [PT-2009-11] SlySoft Multiple Products ElbyCDIO.sys Denial of Service ("Valery Marchuk"
)