The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request.
2008-08-12T23:41:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | broadcom | internet_security_suite | 3.0 | Yes |
Application | ca | host_based_intrusion_prevention_system | r8 | Yes |
Application | ca | internet_security_suite_2008 | * | Yes |
Application | ca | personal_firewall_2007 | * | Yes |
Application | ca | personal_firewall_2008 | * | Yes |