First published: Tue Aug 12 2008(Updated: )
The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Computer Associates Internet Security Suite | ||
CA Host-Based Intrusion Prevention System | =r8 | |
CA Personal Firewall | ||
CA Personal Firewall | ||
Broadcom Internet Security Suite | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2926 has a high severity rating due to its potential to cause system crashes and privilege escalation.
To fix CVE-2008-2926, you should update to the latest version of the affected software which addresses this vulnerability.
CVE-2008-2926 affects CA Host-Based Intrusion Prevention System r8, CA Internet Security Suite, and CA Personal Firewall versions 2007 and 2008.
No, CVE-2008-2926 can only be exploited locally by a user with access to the system.
The potential impact of CVE-2008-2926 includes denial of service through system crashes or possible privilege escalation.