PT-2007-2926 · Microsoft · Ndistapi.Sys+2
Published
2007-03-20
·
Updated
2018-10-16
·
CVE-2007-1537
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP SP2
Microsoft Windows 2003 SP1
Description
The issue concerns weak permissions in the DeviceNdisTapi (NDISTAPI.sys) component, allowing local users to write to the device. This can cause a denial of service, demonstrated by using an IRQL to acquire a spinlock on paged memory via the
NdisTapiDispatch function.Recommendations
For Microsoft Windows XP SP2, update the system to address the weak permissions issue in the DeviceNdisTapi component.
For Microsoft Windows 2003 SP1, update the system to address the weak permissions issue in the DeviceNdisTapi component.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ndistapi.Sys
Windows 2003
Windows Xp