PT-2007-6081 · Microsoft · Windows
Published
2007-09-18
·
Updated
2018-10-15
·
CVE-2007-4967
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Online Armor Personal Firewall version 2.0.1.215
Description
The issue arises from improper validation of certain parameters to System Service Descriptor Table (SSDT) function handlers, allowing local users to cause a denial of service (crash) and possibly gain privileges. This is achieved through unspecified kernel SSDT hooks for various Windows Native API functions, including NtAllocateVirtualMemory, NtConnectPort, NtCreateFile, NtCreateKey, NtCreatePort, NtDeleteFile, NtDeleteValueKey, NtLoadKey, NtOpenFile, NtOpenProcess, NtOpenThread, NtResumeThread, NtSetContextThread, NtSetValueKey, NtSuspendProcess, NtSuspendThread, and NtTerminateThread.
Recommendations
To resolve the issue, update to a version of Online Armor Personal Firewall that properly validates parameters to SSDT function handlers. As a temporary workaround, consider restricting access to the Windows Native API functions until a patch is available.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows