PT-2007-2162 · Comodo · Comodo Firewall Pro
Publicado
2007-02-04
·
Atualizado
2018-10-16
·
CVE-2007-0709
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Comodo Firewall Pro versions 2.4.16.174 and earlier
Description
The issue concerns the
cmdmon.sys component in Comodo Firewall Pro, which fails to validate arguments from user mode for several hooked SSDT functions, including NtCreateSection, NtOpenProcess, NtOpenSection, NtOpenThread, and NtSetValueKey. This allows local users to potentially cause a denial of service, leading to a system crash, and possibly gain privileges by providing invalid arguments.Recommendations
For Comodo Firewall Pro versions 2.4.16.174 and earlier, update to a version later than 2.4.16.174 to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Comodo Firewall Pro