Security Alert: Broadcom Wireless drivers exploited

Security Alert: Broadcom Wireless drivers exploited


If you are using a Broadcom Wireless-N network card or a computer with this card, chances are that you have got the vulnerable version of the Broadcom BCMWL5.SYS wireless device driver installed. The vulnerability allows remote code execution. More information can be found at the Month of Kernel Bugs site. Unfortunately, due to the nature of wireless networking, all that is required of the attacker is to be within range of the vulnerable machine. Because this vulnerability occurs at an extremely low level
within the networking protocol, there may be difficulties in detecting these attacks using standard IDS/IPS methods.

The BCMWL5.SYS driver is bundled with new PCs from HP, Dell, Gateway, eMachines, and other computer manufacturers. Linksys, Zonet, and other wireless card manufactures also provide devices that ship with this driver.

Broadcom has released a fixed driver to their partners, which are in turn providing updates for the affected products. We recommend that you update the wireless driver as soon as possible, if your computer is running a vulnerable version of the Broadcom Wireless driver.

Also avoid using your wireless card to connect to networks in insecure areas, and also be aware of the risk involved when connecting wirelessly.

Download the fixed version of a Broadcom-compatible driver here.