Heap-based buffer overflow in Panda Security Kernel Memory Access Driver 1.0.0.13 allows attackers to execute arbitrary code with kernel privileges via a crafted size input for allocated kernel paged pool and allocated non-paged pool buffers.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1438
Reference (s):
- BID:75715
- URL: http://www.securityfocus.com/bid/75715
- FULLDISC:20151231 CVE-2015-1438 – Arbitrary Code Execution [PSKMAD.sys] In Panda Security – Multiple Products
- URL: http://seclists.org/fulldisclosure/2015/Jul/61
- FULLDISC:20151231 CVE-2015-1438 – Panda Security Multiple Products Arbitrary Code Execution