what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

IRM Security Advisory 14

IRM Security Advisory 14
Posted Dec 28, 2005
Authored by IRM Research, IRM Advisories | Site irmplc.com

RM Security Advisory No. 014 - Sygate Protection Agent 5.0 vulnerability - A low privileged user can disable the security agent

tags | advisory
SHA-256 | d31cb760d8c84be73e419d002d442d2df531f72d5420e40ff4c57ead99aae8bb

IRM Security Advisory 14

Change Mirror Download
----------------------------------------------------------------------
IRM Security Advisory No. 014

Sygate Protection Agent 5.0 vulnerability - A low privileged user can
disable the security agent

Vulnerablity Type / Importance: Security Protection Bypass / High

Problem discovered: November 23rd 2005
Vendor contacted: November 23rd 2005
Advisory published: December 20th 2005
----------------------------------------------------------------------

Abstract:

The Sygate Protection Agent is one of the components within the Sygate
Enterprise Protection software suite. The agent acts as a personal firewall
and detects known Trojans, port scans and common attacks. When an attack is
detected, the product can selectivley block traffic, services or
applications.
A vulnerability has been identified in the product that allows a low
privileged user to disable the Security Protection Agent, which could place
the system being protected at risk of attack.

Description:

There are two executable files in the installation path of the agent,
Smc.exe and SmcGui.exe - there are no shortcuts directly created for
the user. if a standard user double clicks on the smcgui.exe, which
is the management interface (supposedly not accessible to standard
users), the following error is displayed:

"Serious problem reading transaction from pipe - probable loss of
syncronisation a 6"

and the GUI does not execute. However upon killing the process in Task
Manager
the Management GUI appears, the user has full access to the management
interface and can therefore disable the security agent.


Tested Versions:

Sygate Protection Agent 5.0 (build 6144)


Tested Operating Systems:

Windows XP SP1
Windows XP Tablet PC edition


Vendor & Patch Information:

On November 23rd an email was sent to 'security-alert@sygate.com' and
'security@sygate.com', but both of these addresses bounced. IRM have
submitted vulnerabilities to Sygate previously so the email was then sent
to a specific individual at the company, but again, no response was
received. As Sygate has been recently acquired by Symantec, an email was
then sent to security@symantec.com. However, again, no responses were
received.


Workarounds:

IRM are not aware of any workarounds for this issue.


Credits:

Research & Advisory: Mazin Faour and Andy Davis


Disclaimer:

All information in this advisory is provided on an 'as is'
basis in the hope that it will be useful. Information Risk Management
Plc is not responsible for any risks or occurrences caused
by the application of this information.

A copy of this advisory may be found at:

http://www.irmplc.com/advisories.htm

----------------------------------------------------------------------

Information Risk Management Plc.
Kings Building,
Smith Square, London,
United Kingdom
SW1P 3JJ
+44 (0)207 808 6420




Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close