Overview
Microsoft Windows drivers for Intel Centrino wireless adapters fail to properly handle malformed frames. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code.
Description
The Microsoft Windows drivers for Intel Centrino 2200BG and 2915ABG PRO wireless adapters fail to properly handle malformed frames. If a remote attacker within transmitting range of an affected wireless adapter sends a specially crafted frame to that adapter, they may be able to trigger this vulnerability. Affected drivers include w22n50.sys, w22n51.sys, w29n50.sys, and w29n51.sys. For more information refer to INTEL-SA-00001. |
Impact
An unauthenticated, remote attacker may be able to execute arbitrary code with kernel-level privileges. |
Solution
Upgrade Intel drivers |
Disable the affected wireless adapter |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00001&languageid=en-fr
- http://support.intel.com/support/wireless/wlan/sb/cs-005905.htm
- http://support.intel.com/support/wireless/wlan/sb/cs-010623.htm
- http://downloadmirror.intel.com/df-support/11141/ENG/relnotes.htm
- http://www.f-secure.com/weblog/archives/archive-082006.html#00000940
- http://www.f-secure.com/weblog/archives/archive-082006.html#00000938
- ftp://download.intel.com/support/wireless/wlan/sb/3945abgug.pdf
- http://support.intel.com/support/wireless/wlan/pro2200bg/
- ftp://download.intel.com/support/wireless/wlan/pro2200bg/2200BGUG.PDF
- http://www.ciac.org/ciac/bulletins/q-268.shtml
Acknowledgements
This vulnerability was reported in Intel Security Bulletin CS-023065
This document was written by Ryan Giobbi and Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-3992 |
Severity Metric: | 12.72 |
Date Public: | 2006-07-28 |
Date First Published: | 2006-08-07 |
Date Last Updated: | 2007-05-31 13:55 UTC |
Document Revision: | 99 |