RSA Authentication Agent for Web for IIS contains a heap overflow in the handling of chunked input. This could allow a remote, unauthenticated attacker to execute arbitrary code on the server.
RSA Authentication Agent software provides access control for networks, web applications, and operating systems. It is used in conjunction with RSA SecurID Authenticators and Authentication Manager software.
RSA Authentication Agent for Web for IIS contains a heap overflow vulnerability. Using chunked transfer-encoding it is possible to overwrite portions of heap memory, allowing execution of arbitrary code. Exploit code for this vulnerability is publicly available.
A remote, unauthenticated attacker may be able to execute arbitrary code with LocalSystem privileges on the vulnerable server.
Upgrade or patch
This vulnerability was reported by Gary O'leary-Steele of Sec-1.
This document was written by Will Dormann, based on the Sec-1 security advisory .
|Date First Published:||2005-05-11|
|Date Last Updated:||2005-11-07 15:46 UTC|