CVE-2010-4502 describes an integer overflow vulnerability in KmxSbx.sys 6.2.0.22 within CA Internet Security Suite Plus 2010. This flaw allows a local attacker to trigger a buffer overflow via crafted IOCTL arguments, leading to a denial of service (pool corruption) and potential arbitrary code execution. With a CVSS score of 7.2 (high severity) and a FAUCET Risk Score of 86/100, the vulnerability is easily exploitable locally with low attack complexity, enabling full compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog or actively exploited, public exploit code exists on ExploitDB, though there is no evidence of widespread community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:ca:internet_security_suite_plus_2010:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.