RSA.Authentication.Agent.Redirect.Buffer.Overflow

description-logoDescription

This indicates an attempt at exploiting a stack-based buffer-overflow vulnerability in the RSA Authentication Agent for Web.
This vulnerability is caused by a flaw in IISWebAgentIF.dll. A remote attacker may exploit this via a long URL parameter in the Redirect method, resulting in arbitrary code execution.

affected-products-logoAffected Products

SecurID Web Agent 5.2 and 5.3

Impact logoImpact

System compromise.

recomended-action-logoRecommended Actions

Apply the following patch:
ftp://ftp.rsasecurity.com/support/Patches/Ace/Agent/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

References

1