Avast! Internet Security 'aswFW.sys' Driver IOCTL Handling Local Denial of Service Vulnerability
BID:42148
Info
Avast! Internet Security 'aswFW.sys' Driver IOCTL Handling Local Denial of Service Vulnerability
| Bugtraq ID: | 42148 |
| Class: | Unknown |
| CVE: |
CVE-2010-5075 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 03 2010 12:00AM |
| Updated: | Dec 12 2011 09:58PM |
| Credit: | x90c of InetCop Security |
| Vulnerable: |
Avast! Internet Security 5.0 |
| Not Vulnerable: | |
Discussion
Avast! Internet Security 'aswFW.sys' Driver IOCTL Handling Local Denial of Service Vulnerability
Avast! Internet Security is prone to a local denial-of-service vulnerability.
Local attackers can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, code execution may be possible; however, this has not been confirmed.
This issue affects Avast! Internet Security 5.0; other versions may also be affected.
Avast! Internet Security is prone to a local denial-of-service vulnerability.
Local attackers can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, code execution may be possible; however, this has not been confirmed.
This issue affects Avast! Internet Security 5.0; other versions may also be affected.
Exploit / POC
Avast! Internet Security 'aswFW.sys' Driver IOCTL Handling Local Denial of Service Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Avast! Internet Security 'aswFW.sys' Driver IOCTL Handling Local Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
Avast! Internet Security 'aswFW.sys' Driver IOCTL Handling Local Denial of Service Vulnerability
References:
References:
- Avast! Homepage (Avast!)
- Avast! Internet Security 5.0 'aswFW.sys' kernel driver IOCTL Memory Pool Corrupt (x90c of INetCop Security)