Skip to main content

CA Products HIPSEngine XMLSecDB ActiveX File Creation Vulnerability

Last Update Date: 25 Feb 2011 16:40 Release Date: 25 Feb 2011 6225 Views

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in CA Host-Based Intrusion Prevention System (HIPS) and CA Internet Security Suite (ISS), which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a design error in the XMLSecDB ActiveX control installed with the HIPSEngine component, which could allow attackers to create arbitrary files on a vulnerable system by tricking a user into visiting a web page which calls the "SetXml()" and "Save()" methods.


Impact

  • Remote Code Execution

System / Technologies affected

  • CA Host-Based Intrusion Prevention System (HIPS) r8.1
  • CA Internet Security Suite (ISS) 2010

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


  • CA Host-Based Intrusion Prevention System (HIPS) r8.1
    Apply patch RO26950 and set the DWORD "ProtectParser" under "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UmxCfg" to "1".

  • CA Internet Security Suite (ISS) 2010A fix will be available soon

Vulnerability Identifier


Source


Related Link