S24EvMon.exe is a service which is part (at least) of the Intel
PROset/Wireless software. This application is provided by Intel in order to
support intel Wireless Devices based on Spectrum 24 chipsets.
This service uses a shared memory section which is created without the
proper security descriptor, allowing unprivileged users to perform
operations like Delete, Read or Write into the memory. The section is named
?S24EventManagerSharedMemory?
This shared memory is used to store ,in plain text, confidential
information like WEP Key, Passwords...
The successful exploitation of this vulnerability could allow to any
unprivileged user to access confidential information,exposing the network.
An important mitigating factor is that the vulnerability is local,
nevertheless some Malware could take advantage of this flaw.
Further information and exploit code at www.reversemode.com
Regards,
Rubén
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.