The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/27175 | vdb entry patch |
http://secunia.com/advisories/28366 | third party advisory patch vendor advisory |
http://www.netopia.com/support/software/technotes/netoctopus/Removing_the_nantsys_Driver.pdf | patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39503 | vdb entry |
http://www.vupen.com/english/advisories/2008/0062 | vdb entry |
http://securitytracker.com/id?1019161 | vdb entry |
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=636 | third party advisory |