[NT] SecureOL VE2 Information Disclosure
SecuriTeam <[email protected]> 8 Sep 2005 10:20:22 +0200
| Newsgroups | gmane.comp.security.securiteam |
|---|---|
| Message-ID | <[email protected]> |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - SecureOL VE2 Information Disclosure ------------------------------------------------------------------------ SUMMARY <http://www.secureol.com/> VE2 provides "two separate virtual environments (Secured and Public) to ensure corporate security and to provide secured and free access to the WEB while protecting the enterprise". A vulnerability in the way the VE2 product separates the two zones allows attackers residing in the public area to read content from the secured area. DETAILS Vulnerable Systems: * VE2 version 1.05.1008 and prior Immune Systems: * VE2 version 1.05.1009 Windows 16-bit execution support allows direct access to physical memory through \\PhysicalMemory device (which is actually a section) for legacy NTVDM and Virtual Real Mode of the processor, accessing physicalmemory from Public Environment provides direct bridge to Secured Environment processes memory. Proof of concept: The following URL provdes some additional details on the vulnerability: <http://cybermessageboard.xeran.com/secureol/viewtopic.php?t=26> http://cybermessageboard.xeran.com/secureol/viewtopic.php?t=26 ADDITIONAL INFORMATION The information has been provided by <mailto:[email protected]> maxim. ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] In order to subscribe to the mailing list, simply forward this email to: [email protected] ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.