PT-2013-4572 · Novell · Novell Client+1

Guest

·

Published

2013-07-31

·

Updated

2013-07-31

·

CVE-2013-3697

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Novell Client versions 4.91 SP5 Novell Client 2 versions SP2, SP3
Description The issue is related to an integer overflow in kernel drivers, specifically NWFS.SYS and NCPL.SYS, which might allow local users to gain privileges. This can be achieved via a crafted 0x1439EB IOCTL call.
Recommendations For Novell Client version 4.91 SP5, consider restricting access to the NWFS.SYS kernel driver until a patch is available. For Novell Client 2 versions SP2 and SP3, consider disabling the NCPL.SYS kernel driver as a temporary workaround to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3697

Affected Products

Novell Client
Novell Client 2