[NT] SecureOL VE2 Information Disclosure

SecuriTeam <[email protected]> 8 Sep 2005 10:20:22 +0200
Newsgroups gmane.comp.security.securiteam
Message-ID <[email protected]>
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  SecureOL VE2 Information Disclosure
------------------------------------------------------------------------


SUMMARY

 <http://www.secureol.com/> VE2 provides "two separate virtual 
environments (Secured and Public) to ensure corporate security and to 
provide secured and free access to  the WEB while protecting the 
enterprise". A vulnerability in the way the VE2 product separates the two 
zones allows attackers residing in the public area to read content from 
the secured area.

DETAILS

Vulnerable Systems:
 * VE2 version 1.05.1008 and prior

Immune Systems:
 * VE2 version 1.05.1009

Windows 16-bit execution support allows direct access to physical memory 
through \\PhysicalMemory device (which is actually a section) for legacy 
NTVDM and Virtual Real Mode of the processor, accessing physicalmemory 
from Public Environment provides direct bridge to Secured Environment 
processes memory.

Proof of concept:
The following URL provdes some additional details on the vulnerability:
 <http://cybermessageboard.xeran.com/secureol/viewtopic.php?t=26> 
http://cybermessageboard.xeran.com/secureol/viewtopic.php?t=26


ADDITIONAL INFORMATION

The information has been provided by  <mailto:[email protected]> maxim.



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] 
In order to subscribe to the mailing list, simply forward this email to: [email protected] 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any kind. 
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.