<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>WinXP SP2: i2omgmt.sys Privilege Escalation Vulnerability in Security</title>
<link>http://www.dslreports.com/forum/r20473786</link>
<description></description>
<language>en</language>
<pubDate>Fri, 29 Aug 2008 21:50:22 EDT</pubDate>
<lastBuildDate>Fri, 29 Aug 2008 21:50:22 EDT</lastBuildDate>

<item>
<title>Re: WinXP SP2: i2omgmt.sys Privilege Escalation Vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20475498</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : <div class="bquote"><small>said by  dave <A HREF="/useremail/u/156437"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Isn't I2O a dead protocol?<br><br>Do many desktop systems use I2O?<br> </div>A lot of fan drivers and SMC type chips use an I2C protocol though I don't know if they use the win32 API for it or their own implementation (i.e.  your facny CPU/mobo monitoring apps)<br><small>--<br>Ubuntu MOTU Developer and Forums Council</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20475498</guid>
<pubDate>Tue, 13 May 2008 13:09:06 EDT</pubDate>
</item>

<item>
<title>Re: WinXP SP2: i2omgmt.sys Privilege Escalation Vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20475387</link>
<description><![CDATA[<A HREF="/useremail/u/156437"><b>dave</b></A> : Isn't I2O a dead protocol?<br><br>Do many desktop systems use I2O?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20475387</guid>
<pubDate>Tue, 13 May 2008 12:48:04 EDT</pubDate>
</item>

<item>
<title>Re: WinXP SP2: i2omgmt.sys Privilege Escalation Vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20475197</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : Looks like MS has provided an <i><b>incentive</b></i> to install SP3 (pretty please, or we'll leave your machine vulnerable). ;)<br><br>Also from original link: <blockquote><small>quote:</small><hr><b>III. ANALYSIS</b><br>Exploitation allows an attacker to elevate privileges by overwriting arbitrary system memory or executing code within kernel context. An attacker needs to log-in to the target machine to exploit this vulnerability.<br><br>This driver is related to I2O protocol and RAID devices. It is not present by default on every Windows installation. However, iDefense found this driver loaded on several systems we tested.<br><br><b>IV. DETECTION</b><br>iDefense has confirmed the existence of this vulnerability in i2omgmt.sys version 5.1.2600.2180 as installed on some Windows XP SP2 systems. All other Windows releases with this driver, including previous versions, are suspected to be vulnerable.<br><br><b>V. WORKAROUND</b><br>Removing write permissions for "Everyone" appears to prevent access to the vulnerable code. Although no side effects were witnessed in lab tests, normal functionality may be hindered.<hr></blockquote>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20475197</guid>
<pubDate>Tue, 13 May 2008 12:13:19 EDT</pubDate>
</item>

<item>
<title>Re: WinXP SP2: i2omgmt.sys Privilege Escalation Vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20475186</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : Isn't this loaded by default on XP systems? Why wasn't this fixed when the vendor was notified? Grouping together minor bugfixes into a yearly big update is a good idea, but for priviledge escalation vulnerabilities is it really appropriate?<br><small>--<br>Ubuntu MOTU Developer and Forums Council</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20475186</guid>
<pubDate>Tue, 13 May 2008 12:10:45 EDT</pubDate>
</item>

<item>
<title>Re: WinXP SP2: i2omgmt.sys Privilege Escalation Vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20473880</link>
<description><![CDATA[<A HREF="/useremail/u/418397"><b>Lanik</b></A> :  <blockquote><small>quote:</small><hr>VIII. DISCLOSURE TIMELINE<br><br>03/20/2007 Initial vendor notification<br>03/20/2007 Initial vendor response<br>05/12/2008 Coordinated public disclosure<hr></blockquote>Way to go M$ took them over a year to fix this, way to stay on top of it.  :uhh:<br><small>--<br>"If it ain't broke don't fix it."</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20473880</guid>
<pubDate>Tue, 13 May 2008 04:42:42 EDT</pubDate>
</item>

<item>
<title>WinXP SP2: i2omgmt.sys Privilege Escalation Vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20473786</link>
<description><![CDATA[<A HREF="/useremail/u/847301"><b>matunga</b></A> : Local exploitation of an input validation vulnerability within version <b>5.1.2600.2180</b> of <b>i2omgmt.sys</b>, as included with <b>Windows XP</b>, could allow an attacker to execute arbitrary code in the context of the kernel. <br><br>Microsoft has addressed this issue within Windows XP Service Pack 3:<br>&raquo;<A HREF="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=699" >labs.idefense.com/intelligence/v&middot;&middot;&middot;p?id=699</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20473786</guid>
<pubDate>Tue, 13 May 2008 03:26:23 EDT</pubDate>
</item>

</channel>
</rss>
