[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-5724Date: (C)2008-12-26   (M)2023-12-22


The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to DeviceEpfw that overwrites portions of memory.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.2
Exploit Score: 3.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-32917
SECUNIA-33210
ADV-2008-3456
http://www.eset.com/joomla/index.php?option=com_content&task=view&id=4113&Itemid=5
http://www.ntinternals.org/ntiadv0807/ntiadv0807.html
smart-security-epfw-privilege-escalation(47477)

CWE    1
CWE-264

© SecPod Technologies