PT-2007-3147 · Symantec · Spbbcdrv.Sys+3

Publicado

2007-04-02

·

Atualizado

2018-10-16

·

CVE-2007-1793

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Symantec Norton Personal Firewall versions 9.1.0.33 through 9.1.1.7 Symantec Norton Internet Security versions prior to 15.0.0.60
Description: The issue allows local users to cause a denial of service or possibly execute arbitrary code via crafted arguments to the NtCreateMutant and NtOpenEvent functions. This is due to the SPBBCDrv.sys driver not validating certain arguments before passing them to hooked SSDT function handlers.
Recommendations: For Symantec Norton Personal Firewall versions 9.1.0.33 and 9.1.1.7, consider updating to a version later than 9.1.1.7 to resolve the issue. For Symantec Norton Internet Security versions prior to 15.0.0.60, update to version 15.0.0.60 or later to fix the problem. As a temporary workaround, consider restricting access to the NtCreateMutant and NtOpenEvent functions until a patch is available.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-1793

Produtos afetados

Spbbcdrv.Sys
Symantec Antivirus Corporate Edition
Symantec Norton Internet Security
Symantec Norton Personal Firewall