Computer Associates Host Intrusion Prevention System (HIPS) drivers (1) Core kmxstart.sys 6.5.4.31 and (2) Firewall kmxfw.sys 6.5.4.10 allow local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-6935
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34818
http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97729
http://www.securityfocus.com/bid/21140
http://www.securityfocus.com/archive/1/458040/100/200/threaded
http://www.securityfocus.com/archive/1/452286/100/0/threaded
http://www.securityfocus.com/archive/1/451952/100/0/threaded
http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=38