CVE-2008-2926: Input Validation
The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2926?
CVE-2008-2926 has a high severity rating due to its potential to cause system crashes and privilege escalation.
How do I fix CVE-2008-2926?
To fix CVE-2008-2926, you should update to the latest version of the affected software which addresses this vulnerability.
What types of systems are affected by CVE-2008-2926?
CVE-2008-2926 affects CA Host-Based Intrusion Prevention System r8, CA Internet Security Suite, and CA Personal Firewall versions 2007 and 2008.
Can CVE-2008-2926 be exploited remotely?
No, CVE-2008-2926 can only be exploited locally by a user with access to the system.
What is the potential impact of CVE-2008-2926?
The potential impact of CVE-2008-2926 includes denial of service through system crashes or possible privilege escalation.