Zero-friction vulnerability management platform

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CA kmxfw.sys Code Execution and DoS Vulnerabilities

Information

Severity

Severity

High

Family

Family

Denial of Service

CVSSv2 Base

CVSSv2 Base

7.2

CVSSv2 Vector

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

14 years ago

Modified

Modified

3 years ago

Summary

This host is running CA Product(s), which is prone to Local Code Execution and Denial of Service Vulnerabilities.

Insight

Insight

Multiple flaw are due to insufficient verification/validation of IOCTL requests by the kmxfw.sys driver.

Affected Software

Affected Software

CA Internet Security Suite 2007 (v3.2) with CA Personal Firewall 2007 (v9.1) Engine version 1.2.260 and below CA Internet Security Suite 2008 (v4.0) with CA Personal Firewall 2008 (v10.0) Engine version 1.2.260 and below CA Personal Firewall 2007 (v9.1) with Engine version 1.2.260 and below CA Personal Firewall 2008 (v10.0) with Engine version 1.2.260 and below CA Host-Based Intrusion Prevention System r8

Solution

Solution

Ensure the latest engine is installed by using the built-in update mechanism and for Host-Based Intrusion Prevention System.

Common Vulnerabilities and Exposures (CVE)