Twenty Year Anniversary

ISS For Business 14.0.1400.2029 Blue Screen Of Death

ISS For Business 14.0.1400.2029 Blue Screen Of Death
Posted Jul 13, 2018
Authored by Felipe Xavier Oliveira

In MicroWorld eScan Internet Security Suite (ISS) for Business version 14.0.1400.2029, the driver econceal.sys allows a non-privileged user to send a 0x830020E0 IOCTL request to \\.\econceal to cause a denial of service (BSOD).

tags | advisory, denial of service
advisories | CVE-2018-10018, CVE-2018-10098
MD5 | e43f0732680669dac8762679657968d3

ISS For Business 14.0.1400.2029 Blue Screen Of Death

Change Mirror Download
=====[ Tempest Security Intelligence - ADV-24/2018 ]===

eScan ISS for Business v14.0.1400.2029 - BSOD through of a IOCTL
Author: Filipe Xavier Oliveira
Tempest Security Intelligence - Recife, Pernambuco - Brazil

=====[ Table of Contents
]=====================================================

* Overview
* Detailed description
* Timeline of disclosure
* Thanks & Acknowledgements
* References

=====[ Overview
]==============================================================

* System affected : eScan ISS for Business[1].
* Software Version : 14.0.1400.2029 (other versions may also be affected).
* Impact : A user may be affected by opening a malicious executable,

=====[ Detailed description
]==================================================

In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys
allows a non-privileged user to send a 0x830020E0 IOCTL request to
\\.\econceal to cause a denial of service (BSOD).

=====[ Aggravating factors ]===================================================

A malicious executable can cause a bsod on the system through the driver from antivirus.

=====[ Timeline of disclosure
]===============================================

04/17/2018 - Vulnerability reported.
04/21/2018 - The vendor receive and will check the vulnerability.

07/12/2018 - The vendor did not respond.

07/12/2018 - CVE assigned [2]

=====[ Thanks & Acknowledgements
]============================================

- Tempest Security Intelligence / Tempest's Pentest Team [3]

=====[ References
]===========================================================

[1] https://www.escanav.com/en/windows-antivirus/corporate-edition-with-hybrid.asp

[2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10098
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10018>

[3] http://www.tempest.com.br <http://www.tempest.com.br/>

=====[ EOF
]====================================================================

--
Filipe Oliveira
Tempest Security Intelligence



Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

September 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    1 Files
  • 2
    Sep 2nd
    3 Files
  • 3
    Sep 3rd
    15 Files
  • 4
    Sep 4th
    15 Files
  • 5
    Sep 5th
    18 Files
  • 6
    Sep 6th
    18 Files
  • 7
    Sep 7th
    15 Files
  • 8
    Sep 8th
    2 Files
  • 9
    Sep 9th
    2 Files
  • 10
    Sep 10th
    16 Files
  • 11
    Sep 11th
    17 Files
  • 12
    Sep 12th
    15 Files
  • 13
    Sep 13th
    29 Files
  • 14
    Sep 14th
    21 Files
  • 15
    Sep 15th
    3 Files
  • 16
    Sep 16th
    1 Files
  • 17
    Sep 17th
    15 Files
  • 18
    Sep 18th
    16 Files
  • 19
    Sep 19th
    29 Files
  • 20
    Sep 20th
    18 Files
  • 21
    Sep 21st
    5 Files
  • 22
    Sep 22nd
    2 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close