PT-2007-3147 · Symantec · Spbbcdrv.Sys+3
Publicado
2007-04-02
·
Atualizado
2018-10-16
·
CVE-2007-1793
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Symantec Norton Personal Firewall versions 9.1.0.33 through 9.1.1.7
Symantec Norton Internet Security versions prior to 15.0.0.60
Description:
The issue allows local users to cause a denial of service or possibly execute arbitrary code via crafted arguments to the
NtCreateMutant and NtOpenEvent functions. This is due to the SPBBCDrv.sys driver not validating certain arguments before passing them to hooked SSDT function handlers.Recommendations:
For Symantec Norton Personal Firewall versions 9.1.0.33 and 9.1.1.7, consider updating to a version later than 9.1.1.7 to resolve the issue.
For Symantec Norton Internet Security versions prior to 15.0.0.60, update to version 15.0.0.60 or later to fix the problem.
As a temporary workaround, consider restricting access to the
NtCreateMutant and NtOpenEvent functions until a patch is available.Exploit
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Spbbcdrv.Sys
Symantec Antivirus Corporate Edition
Symantec Norton Internet Security
Symantec Norton Personal Firewall