61946vdb entry
http://osvdb.org/61946 CVE-2010-1591
Rising AntiVirus 2008/2009/2010 - Local Privilege Escalation
Record summary
CVE-2010-1591 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys, (2) HookNtos.sys, (3) HOOKREG.sys, or (4) HookSys.sys device driver; or the (5) RsNTGdi.sys kernel module, reachable through \Device\RSNTGDI.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRising AntiVirus 2008/2009/2010 - Local Privilege EscalationExploitDB exploitby DlrowNot analyzed1 file
References
838335Third-party advisory
http://secunia.com/advisories/38335 ntinternals.org
http://www.ntinternals.org/ntiadv0805/ntiadv0805.html ntinternals.org
http://www.ntinternals.org/ntiadv0902/ntiadv0902.html 37951vdb entry
http://www.securityfocus.com/bid/37951 ADV-2010-0218vdb entry
http://www.vupen.com/english/advisories/2010/0218 rising-antivirus-drivers-priv-escalation(55869)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/55869 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-1591