CVE-2007-2523

CA Anti-Virus for the Enterprise r8 and Threat Manager r8 - Privilege Escalation via Task Service File Mapping

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2523. PoCs published by binagres.

AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in Computer Associates eTrust Antivirus Agent r8 via the 'INOQSIQSYSINFO' file mapping. It leverages a long file path to trigger the overflow in the QSIGetQueuePath function, bypassing stack protection mechanisms.

Description

CA Anti-Virus for the Enterprise r8 and Threat Manager r8 before 20070510 use weak permissions (NULL security descriptor) for the Task Service shared file mapping, which allows local users to modify this mapping and gain privileges by triggering a stack-based buffer overflow in InoCore.dll before 8.0.448.0.

Exploits (1)

exploitdb WORKING POC VERIFIED
by binagres · cremotewindows
https://www.exploit-db.com/exploits/30019

This exploit targets a stack-based buffer overflow in Computer Associates eTrust Antivirus Agent r8 via the 'INOQSIQSYSINFO' file mapping. It leverages a long file path to trigger the overflow in the QSIGetQueuePath function, bypassing stack protection mechanisms.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Computer Associates eTrust Antivirus Agent r8 (with INOCORE.DLL 8.0.403.0)
No auth needed
Prerequisites: Access to the target system's file mapping 'Global\INOQSIQSYSINFO' · Target system running eTrust Antivirus Agent r8
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018043
Various Sources x_refsource_misc
http://blog.48bits.com/?p=103
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1750
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23906
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/788416
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/34586
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25202
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/468306/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=530
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063275.html

Scores

EPSS 0.0138
EPSS Percentile 68.6%

Details

Status published
Products (2)
broadcom/integrated_threat_management 8.0
ca/anti-virus_for_the_enterprise 8
Published May 11, 2007
Tracked Since Feb 18, 2026