[CVE-2012-2273] Comodo Internet Security <5.10 BSOD (Win7 x64)

[affected software]
Comodo Internet Security, until 5.9

BSOD under Windows 7 x64 if a 32b PE with a kernel ImageBase is executed.

such files are very unusual, but work perfectly if the PE contains
relocations, as shown at http://pe.corkami.com#ImageBase and

PoCs downloadable on http://pe.corkami.com, files: tls_reloc ibkernel
ibkmanual reloccrypt

Ange Albertini (corkami.com)

[vendor communication]
5th January 2012 - details shared with the vendor
23th January 2012 - patch is planned
12th March 2012 - bug are fixed in 5.10

from http://www.comodo.com/home/download/release-notes.php?p=anti-malware

5.10.228257.2253: 12 March, 2012
* IMPROVED! Compatibility with other security suites is improved in
Windows 7 x64
* FIXED! BSOD when corrupted executables are loaded in memory in Windows 7 x64
* FIXED! HIPS can leak process handles with a special set of access rights
* FIXED! Smart scan crashes under certain circumstances

update to 5.10 or later

Relevant Pages

  • Re: Sptd.sys problem
    ... mode, bsod appears. ... Is the edition of Windows that you use (Home, Professional, 2002 Media ... If the x64 edition, did you make sure to download the x64 version of their ... During the boot into Windows' safe mode, you will see a list of drivers ...
  • Re: Windows BSOD at olympics
    ... Here is a really funny story about Window's BSOD. ... Was it a legit copy of Windows? ... This just made the olympics opening ceremony much better. ... And across the ceiling of where you're sitting, dozens of projected screens of people playing games, someone photochopping an image of the CEO, someone showing off their pr0n collection. ...
  • Re: Vista killed my HP DV7
    ... on Vista x64 issues. ... When I booted on Friday evening I got a Windows Defender error asking ... also occasionally BSOD, especially when trying to enter Windows Update. ... didn't get a BSOD I got, no price for guessing, another error message ...
  • p5n32-sli se deluxe and Vista x64 and 2gb (slow enough) then 4gb (horribly slow issues)
    ... Has anyone had trouble running Vista x64 on this motherboard.. ... I have a 1.86 Core2 CPU, the memory is the Corsair Twin2x2048-6400 ... opening windows was horrible.. ...
  • Re: shutdown.exe on windows 2003 server 64 bit
    ... heads up: shutdown.exe on windows 64 ... I was setting up an automated shutdown script on the UPS setup to stop some ... An equivalent script runs fine on SBS 2003 but on windows x64 all goes well ... when using windows server x64 it is impossible to run ...