Rising Antivirus 2010 RsAssist.sys Privilege Escalation Vulnerability

Description
A vulnerability has been reported in Rising Antivirus 2010, which can be exploited by malicious, local users to potentially gain escalated privileges.

The vulnerability is caused due to an error in the RsAssist.sys driver when handling IOCTLs. This can be exploited to potentially execute arbitrary code in kernel space via a specially crafted IOCTL.

The vulnerability is reported in RISING Antivirus 2010 versions prior to 22.0.3.54.

Solution
Update to version 22.0.3.54 or later.

Provided and/or discovered by
NT Internals

Original Advisory
NT Internals:
http://www.ntinternals.org/ntiadv1001/ntiadv1001.html

发表评论?

0 条评论。

发表评论