matousec.com (site map)

Poll

Your favourite antivirus families?

  Comodo (31.62%)

  NOD32 (Eset) (21.03%)

  Kaspersky (17.74%)

  AntiVir (Avira) (16.66%)

  avast! (13.4%)

  Symantec (4.16%)

  AVG (3.79%)

  Dr.Web (3.43%)

more

results

Advisory 2006-09-01.01

BlackICE Insufficient validation of arguments of NtOpenSection Vulnerability

Basic information:


Release date: September 01, 2006

Last update: September 19, 2006

Severity:Medium

Character:Complete system control

Status:Unknown

Testing program: BTP00000P003BI.zip

Description:

Hooking SSDT functions requires extra caution. SSDT function handlers are executed in the kernel mode but their callers are executed in the user mode. Hence all function arguments come from the user mode. This is why it is necessary to validate these arguments properly. Otherwise a simple user call can easily crash the whole system. This bug usually results in a system crash. However, it may happen that this bug is even more dangerous and may lead to the execution of an arbitrary code in the privileged kernel mode.

BlackICE fails to validate the third argument of NtOpenSection. A call with invalid values in this argument can cause a system crash because of an error in RapDrv.sys.

Vulnerable software:

Events:

References: