Vulnerabilities > CVE-2010-4502 - Numeric Errors vulnerability in CA Internet Security Suite Plus 2010

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
ca
CWE-189
exploit available

Summary

Integer overflow in KmxSbx.sys 6.2.0.22 in CA Internet Security Suite Plus 2010 allows local users to cause a denial of service (pool corruption) and execute arbitrary code via crafted arguments to the 0x88000080 IOCTL, which triggers a buffer overflow.

Vulnerable Configurations

Part Description Count
Application
Ca
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionCA Internet Security Suite 2010 - KmxSbx.sys Kernel Pool Overflow (0day). CVE-2010-4502. Local exploit for windows platform
fileexploits/windows/local/15624.txt
idEDB-ID:15624
last seen2016-02-01
modified2010-11-28
platformwindows
port
published2010-11-28
reporterNikita Tarakanov
sourcehttps://www.exploit-db.com/download/15624/
titleCA Internet Security Suite 2010 - KmxSbx.sys Kernel Pool Overflow 0day
typelocal