>> Intel LAN Driver "NDIS.SYS" Local Buffer Overflow Privilege Escalation Vulnerability
Title : Intel LAN Driver "NDIS.SYS" Local Buffer Overflow Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2006-4871 CVE ID : CVE-2006-6385
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-12-06
Technical Description
A vulnerability has been identified in PCI, PCI-X and PCIe Intel network adapter drivers, which could be exploited by local attackers to obtain elevated privileges. This flaw is due to a buffer overflow error in the "QueryInformationHandler" routine within NDIS.SYS, which could allow malicious users to execute arbitrary commands with kernel-level privileges.