Novell Client for Windows NWFILTER.SYS privilege escalation
| novell-client-nwfilter-privilege-escalation (38434) |
Description:
Novell Client for Windows could allow a local attacker to gain elevated privileges on the system, caused by improper validation of user-supplied input in the NWFILTER.SYS driver. By sending a specially-crafted IOCTL request using a METHOD_NEITHER buffering mode, an attacker could exploit this vulnerability to execute arbitrary code on the system with kernel level privileges.
Platforms Affected:
- Novell, Client 4.91 SP4
- Novell, Client 4.91 SP2
- Novell, Client 4.91 SP1a
- Novell, Client 4.91 SP3
Remedy:
Refer to Novell Security Alert 3260263 for patch, upgrade, or suggested workaround information. See References.
Consequences:
Gain Privileges
References:
- iDefense Labs PUBLIC ADVISORY: 11.12.07, Novell NetWare Client NWFILTER.SYS Local Privilege Escalation Vulnerability at http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=626.
- Novell Security Alert 3260263, Architectural and security problems with NWFILTER.SYS at https://secure-support.novell.com/KanisaPlatform/Publishing/98/3260263_f.SAL_Public.html.
- BID-26420: Novell Client for Windows NWFILTER.SYS Local Privilege Escalation Vulnerability
- CVE-2007-5667: NWFILTER.SYS in Novell Client 4.91 SP 1 through SP 4 for Windows 2000, XP, and Server 2003 makes the \.\nwfilter device available for arbitrary user-mode input via METHOD_NEITHER IOCTLs, which allows local users to gain privileges by passing a kernel address as an argument and overwriting kernel memory locations.
- FrSIRT/ADV-2007-3846: Novell Client for Windows NWFILTER.SYS Privilege Escalation Issue
- SA27678: Novell Client NWFILTER.SYS Privilege Escalation Vulnerability
- SECTRACK ID: 1018943: Novell Client Lets Local Users Gain Kernel Level Privileges
Reported:
Nov 12, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
