Multiple Symantec Antivirus IOCTL device driver privilege escalation
| symantec-ioctl-privilege-escalation (29360) |
Description:
Multiple Symantec Antivirus products could allow a local attacker to gain elevated privileges on the system, caused by a vulnerability in the NAVEX15.SYS and NAVENG.SYS device drivers. By sending a specially-crafted Irp to the IOCTL function, a local attacker could overwrite supplied addresses and execute arbitrary code on the system with kernel level privileges.
Platforms Affected:
- Symantec, AntiVirus Corporate
- Symantec, AntiVirus for BlueCoat Security
- Symantec, AntiVirus for CacheFlow
- Symantec, AntiVirus for ClearSwift
- Symantec, AntiVirus for Inktomi
- Symantec, AntiVirus for Microsoft ISA
- Symantec, AntiVirus for NetApp
- Symantec, Brightmail AntiSpam
- Symantec, Client Security
- Symantec, Mail Security Domino
- Symantec, Mail Security Exchange
- Symantec, Mail Security SMTP
- Symantec, Norton AntiVirus
- Symantec, Norton Internet Security
- Symantec, Norton System Works
- Symantec, Scan Engine
- Symantec, Web Security
Remedy:
Refer to Symantec Advisory SYM06-020 for patch, upgrade, or suggested workaround information. See References.
Consequences:
Gain Privileges
References:
- BugTraq Mailing List, Thu Oct 05 2006 - 17:05:50 CDT, [Reversemode Advisory] Symantec Antivirus Engine Privilege Escalation at http://archives.neohapsis.com/archives/bugtraq/2006-10/0074.html.
- iDEFENSE ADVISORY: 10.05.06, Symantec AntiVirus IOCTL Kernel Privilege Escalation Vulnerability at http://www.idefense.com/intelligence/vulnerabilities/display.php?id=417.
- SYM06-020 , Symantec Device Driver Elevation of Privilege at http://www.symantec.com/avcenter/security/Content/2006.10.05a.html.
- BID-20360: Symantec AntiVirus IOCTL Kernel Privilege Escalation Vulnerability
- CVE-2006-4927: The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to the IOCTL functions (1) 0x222AD3, (2) 0x222AD7, and (3) 0x222ADB.
- SA22288: Symantec Products IOCTL Handler Privilege Escalation
- SECTRACK ID: 1016994: Norton Anti-Virus NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges
- SECTRACK ID: 1016995: Norton Internet Security NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges
- SECTRACK ID: 1016996: Norton System Works NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges
- SECTRACK ID: 1016997: Symantec Anti Virus NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges
- SECTRACK ID: 1016998: Symantec Web Security NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges
- SECTRACK ID: 1016999: Symantec Scan Engine NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges
- SECTRACK ID: 1017000: Symantec Brightmail NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges
- SECTRACK ID: 1017001: Symantec Mail Security NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges
- SECTRACK ID: 1017002: Symantec Client Security NAVEX15/NAVENG Device Drivers Let Local Users Gain Kernel Level Privileges
- US-CERT VU#946820: Symantec products fail to properly limit device driver access to kernel memory
- VUPEN/ADV-2006-3928: Symantec Anti-Virus Engine Device Driver IOCTL Privilege Escalation Vulnerability
Reported:
Oct 05, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
