Novell Client for Windows nicm.sys privilege escalation
| novell-client-nicm-privilege-escalation (39576) |
Description:
Novell Client for Windows could allow a local attacker to gain elevated privileges on the system, caused by improper validation of user-supplied input in the nicm.sys driver. By sending a specially-crafted IOCTL request using a METHOD_NEITHER buffering mode, an attacker could exploit this vulnerability to execute arbitrary code on the system with kernel level privileges.
Platforms Affected:
- Novell, NetWare Client 4.91 SP4
Remedy:
Apply the patch for this vulnerability (491psp3_4_nicm.zip), available from the Novell Web site. See References.
Consequences:
Gain Privileges
References:
- iDefense PUBLIC ADVISORY: 01.09.08, Novell NetWare Client nicm.sys Local Privilege Escalation Vulnerability at http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=637.
- Novell Web site, Novell Client 4.91 Post-SP3/4 NICM.SYS at http://download.novell.com/Download?buildid=4FmI89wOmg4~.
- BID-27209: Novell Client for Windows 'nicm.sys 'Local Privilege Escalation Vulnerability
- BID-29109: Novell Client for Windows Forgotten Password Local Privilege Escalation Vulnerability
- CVE-2007-5762: NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode.
- SA28396: Novell Client nicm.sys Privilege Escalation Vulnerability
- SECTRACK ID: 1019172: NetWare 'nicm.sys' Driver Lets Local Users Gain Kernel Level Privileges
- VUPEN/ADV-2008-0088: Novell Client nicm.sys Driver Local Privilege Escalation Vulnerability
Reported:
Jan 09, 2008
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
