blog.48bits.com
http://blog.48bits.com/?p=103 CVE-2007-2523
CA (Multiple Products) - Console Server / 'InoCore.dll' Remote Code Execution
Record summary
CVE-2007-2523 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
CA Anti-Virus for the Enterprise r8 and Threat Manager r8 before 20070510 use weak permissions (NULL security descriptor) for the Task Service shared file mapping, which allows local users to modify this mapping and gain privileges by triggering a stack-based buffer overflow in InoCore.dll before 8.0.448.0.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCA (Multiple Products) - Console Server / 'InoCore.dll' Remote Code ExecutionExploitDB exploitby binagresNot analyzed1 file
References
1220070509 Computer Associates eTrust InoTask.exe Antivirus Buffer Overflow VulnerabilityThird-party advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=530 20050711 [CAID 35330, 35331]: CA Anti-Virus, CA Threat Manager, and CA Anti-Spyware Console Login and File Mapping Vulnerabilitiesmailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063275.html 25202Third-party advisory
http://secunia.com/advisories/25202 supportconnectw.ca.comConfirmation
http://supportconnectw.ca.com/public/antivirus/infodocs/caav-secnotice050807.asp VU#788416Third-party advisory
http://www.kb.cert.org/vuls/id/788416 34586vdb entry
http://www.osvdb.org/34586 20070511 Computer Associates eTrust InoTask.exe Antivirus Buffer Overflow Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/468306/100/0/threaded 23906vdb entry
http://www.securityfocus.com/bid/23906 1018043vdb entry
http://www.securitytracker.com/id?1018043 ADV-2007-1750vdb entry
http://www.vupen.com/english/advisories/2007/1750 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-2523