6.9

CVE-2007-3673

Exploit

Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\symTDI\, which results in memory overwrite.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SymantecClient Security Version2.0
SymantecClient Security Version3.0
SymantecClient Security Version3.1
SymantecNorton Antispam Version2005
SymantecNorton Antivirus Version9.0 Editioncorporate
SymantecNorton Antivirus Version9.0.0.338 Editioncorporate
SymantecNorton Antivirus Version9.0.1 Editioncorporate
SymantecNorton Antivirus Version9.0.1.1.1000 Editioncorporate
SymantecNorton Antivirus Version9.0.1.1000 Editioncorporate
SymantecNorton Antivirus Version9.0.2 Editioncorporate
SymantecNorton Antivirus Version9.0.2.1000 Editioncorporate
SymantecNorton Antivirus Version9.0.3.1000 Editioncorporate
SymantecNorton Antivirus Version9.0.4 Editioncorporate
SymantecNorton Antivirus Version9.0.5 Editioncorporate
SymantecNorton Antivirus Version9.0.5.1100 Editioncorporate
SymantecNorton Antivirus Version10.0 Editioncorporate
SymantecNorton Antivirus Version10.1 Editioncorporate
SymantecNorton Antivirus Version2005
SymantecNorton Antivirus Version2006
SymantecNorton System Works Version2005
SymantecNorton System Works Version2006
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.352
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C