PT-2007-2926 · Microsoft · Ndistapi.Sys+2

Published

2007-03-20

·

Updated

2018-10-16

·

CVE-2007-1537

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP SP2 Microsoft Windows 2003 SP1
Description The issue concerns weak permissions in the DeviceNdisTapi (NDISTAPI.sys) component, allowing local users to write to the device. This can cause a denial of service, demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
Recommendations For Microsoft Windows XP SP2, update the system to address the weak permissions issue in the DeviceNdisTapi component. For Microsoft Windows 2003 SP1, update the system to address the weak permissions issue in the DeviceNdisTapi component.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1537

Affected Products

Ndistapi.Sys
Windows 2003
Windows Xp