PT-2007-2162 · Comodo · Comodo Firewall Pro

Publicado

2007-02-04

·

Atualizado

2018-10-16

·

CVE-2007-0709

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Comodo Firewall Pro versions 2.4.16.174 and earlier
Description The issue concerns the cmdmon.sys component in Comodo Firewall Pro, which fails to validate arguments from user mode for several hooked SSDT functions, including NtCreateSection, NtOpenProcess, NtOpenSection, NtOpenThread, and NtSetValueKey. This allows local users to potentially cause a denial of service, leading to a system crash, and possibly gain privileges by providing invalid arguments.
Recommendations For Comodo Firewall Pro versions 2.4.16.174 and earlier, update to a version later than 2.4.16.174 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0709

Produtos afetados

Comodo Firewall Pro