CVE-2010-1591 Information

Description

Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs including 0x83003C07 which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys (2) HookNtos.sys (3) HOOKREG.sys or (4) HookSys.sys device driver; or the (5) RsNTGdi.sys kernel module reachable through \Device\RSNTGDI.

Reference

http://osvdb.org/61946 http://secunia.com/advisories/38335 http://www.ntinternals.org/ntiadv0805/ntiadv0805.html http://www.ntinternals.org/ntiadv0902/ntiadv0902.html http://www.securityfocus.com/bid/37951 http://www.vupen.com/english/advisories/2010/0218 https://exchange.xforce.ibmcloud.com/vulnerabilities/55869

Share on: