CERT-In Vulnerability Note
CIVN-2007-0148
Cisco Security Agent for Windows System Driver Remote Buffer Overflow Vulnerability
Original Issue Date:December 07, 2007
Severity Rating: HIGH
Systems Affected
All versions of Cisco Security Agent for Windows, either managed or standalone, are affected
Overview
A vulnerability has been reported in Cisco Security Agent for Windows. A remote user can execute arbitrary code on the target system by sending specially crafted script to TCP port 139 or 445 on to trigger a buffer overflow. The code will run with kernel level privileges.
Description
To get protected from viruses, worms and attacks, some Cisco products are required to be integrated with Cisco security agent which is security software possibly running on a window machine. An attacker may corrupt windows kernel memory by overflowing the buffer. The vulnerability is triggered when Cisco Security Agent is processing a crafted TCP segment destined to TCP port 139 or 445. These ports are used by the Microsoft Server Message Block SMB protocol. The blocking of traffic destined to TCP ports 139 and 445 is enabled by default and is not user-configurable.
The vulnerability can be exploited remotely via the network. Exploitation of this vulnerability will lead to a Windows stop error kernel panic, or blue screen error , or to arbitrary code execution.
Workaround
- Appropriate ACL may be used to allow the traffic only from trusted host to tcp port 139 and 445.
Vendor Information
CISCO
http://www.cisco.com/warp/public/707/cisco-sa-20071205-csa.shtml#@ID
References
Security Focus
http://www.securityfocus.com/archive/1/484625
Security Tracker
http://www.securitytracker.com/alerts/2007/Dec/1019046.html
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|