PT-2007-3147 · Symantec · Spbbcdrv.Sys+3

Published

2007-04-02

·

Updated

2018-10-16

·

CVE-2007-1793

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Symantec Norton Personal Firewall versions 9.1.0.33 through 9.1.1.7 Symantec Norton Internet Security versions prior to 15.0.0.60
Description: The issue allows local users to cause a denial of service or possibly execute arbitrary code via crafted arguments to the NtCreateMutant and NtOpenEvent functions. This is due to the SPBBCDrv.sys driver not validating certain arguments before passing them to hooked SSDT function handlers.
Recommendations: For Symantec Norton Personal Firewall versions 9.1.0.33 and 9.1.1.7, consider updating to a version later than 9.1.1.7 to resolve the issue. For Symantec Norton Internet Security versions prior to 15.0.0.60, update to version 15.0.0.60 or later to fix the problem. As a temporary workaround, consider restricting access to the NtCreateMutant and NtOpenEvent functions until a patch is available.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-1793

Affected Products

Spbbcdrv.Sys
Symantec Antivirus Corporate Edition
Symantec Norton Internet Security
Symantec Norton Personal Firewall