Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CA kmxfw.sys Code Execution and DoS Vulnerabilities
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
This host is running CA Product(s), which is prone to Local Code Execution and Denial of Service Vulnerabilities.
Insight
Insight
Multiple flaw are due to insufficient verification/validation of IOCTL requests by the kmxfw.sys driver.
Affected Software
Affected Software
CA Internet Security Suite 2007 (v3.2) with CA Personal Firewall 2007 (v9.1) Engine version 1.2.260 and below CA Internet Security Suite 2008 (v4.0) with CA Personal Firewall 2008 (v10.0) Engine version 1.2.260 and below CA Personal Firewall 2007 (v9.1) with Engine version 1.2.260 and below CA Personal Firewall 2008 (v10.0) with Engine version 1.2.260 and below CA Host-Based Intrusion Prevention System r8
Solution
Solution
Ensure the latest engine is installed by using the built-in update mechanism and for Host-Based Intrusion Prevention System.
Common Vulnerabilities and Exposures (CVE)
References
- http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36560
- http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36559
- http://securitytracker.com/alerts/2008/Aug/1020662.html
- http://securitytracker.com/alerts/2008/Aug/1020663.html
- http://www.trapkit.de/advisories/TKADV2008-006.txt
- http://seclists.org/fulldisclosure/2008/Aug/0256.html
- https://support.ca.com/irj/portal/anonymous/SolutionResults?aparNo=RO0