[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-5633Date: (C)2007-10-23   (M)2023-12-22


Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, allows local users to read or write arbitrary MSRs, and gain privileges and load unsigned drivers, via the (1) IOCTL_RDMSR 0x9C402438 and (2) IOCTL_WRMSR 0x9C40243C IOCTLs to Devicespeedfan, as demonstrated by an IOCTL_WRMSR action on MSR_LSTAR.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.2
Exploit Score: 3.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-26123
SECUNIA-27312
OSVDB-41842
http://www.bugtrack.almico.com/view.php?id=987
http://www.reversemode.com/index.php?option=com_content&task=view&id=42&Itemid=1
speedfan-ioctl-privilege-escalation(37298)

CPE    1
cpe:/o:microsoft:windows_vista:::x64

© SecPod Technologies