PT-2007-2161 · Comodo · Comodo Firewall Pro

Publicado

2007-02-04

·

Atualizado

2018-10-16

·

CVE-2007-0708

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Comodo Firewall Pro versions prior to 2.4.16.174
Description The issue concerns the cmdmon.sys component in Comodo Firewall Pro, which fails to validate arguments from user mode for the (1) NtConnectPort and (2) NtCreatePort hooked SSDT functions. This allows local users to potentially cause a denial of service, resulting in a system crash, and possibly gain privileges by providing invalid arguments.
Recommendations For versions prior to 2.4.16.174, update to version 2.4.16.174 or later to resolve the issue. As a temporary workaround, consider restricting access to the cmdmon.sys component to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0708

Produtos afetados

Comodo Firewall Pro