7.2

CVE-2007-5667

NWFILTER.SYS in Novell Client 4.91 SP 1 through SP 4 for Windows 2000, XP, and Server 2003 makes the \.\nwfilter device available for arbitrary user-mode input via METHOD_NEITHER IOCTLs, which allows local users to gain privileges by passing a kernel address as an argument and overwriting kernel memory locations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Novell ≫ Client Version 4.91 Update sp1
   Microsoft ≫ Windows 2000 Edition adv_srv
   Microsoft ≫ Windows 2000 Edition datacenter_srv
   Microsoft ≫ Windows 2000 Edition pro
   Microsoft ≫ Windows 2000 Edition srv
   Microsoft ≫ Windows 2000 Edition srv Lang ja
   Microsoft ≫ Windows 2000 Version -
   Microsoft ≫ Windows 2003 Server Edition itanium
   Microsoft ≫ Windows 2003 Server Edition std
   Microsoft ≫ Windows 2003 Server Edition wed
   Microsoft ≫ Windows 2003 Server Edition x64
   Microsoft ≫ Windows 2003 Server Edition x64-std
   Microsoft ≫ Windows 2003 Server Edition xp-64bit
   Microsoft ≫ Windows 2003 Server Version -
   Microsoft ≫ Windows Server 2003
   Microsoft ≫ Windows Xp Edition 64bit
   Microsoft ≫ Windows Xp Edition embedded
   Microsoft ≫ Windows Xp Edition ibm_oem
   Microsoft ≫ Windows Xp Edition media_center
   Microsoft ≫ Windows Xp Edition pro
   Microsoft ≫ Windows Xp Edition tablet_pc
   Microsoft ≫ Windows Xp Edition x64
   Microsoft ≫ Windows Xp Version -
Novell ≫ Client Version 4.91 Update sp2
   Microsoft ≫ Windows 2000 Edition adv_srv
   Microsoft ≫ Windows 2000 Edition datacenter_srv
   Microsoft ≫ Windows 2000 Edition pro
   Microsoft ≫ Windows 2000 Edition srv
   Microsoft ≫ Windows 2000 Edition srv Lang ja
   Microsoft ≫ Windows 2000 Version -
   Microsoft ≫ Windows 2003 Server Edition itanium
   Microsoft ≫ Windows 2003 Server Edition std
   Microsoft ≫ Windows 2003 Server Edition wed
   Microsoft ≫ Windows 2003 Server Edition x64
   Microsoft ≫ Windows 2003 Server Edition x64-std
   Microsoft ≫ Windows 2003 Server Edition xp-64bit
   Microsoft ≫ Windows 2003 Server Version -
   Microsoft ≫ Windows Server 2003
   Microsoft ≫ Windows Xp Edition 64bit
   Microsoft ≫ Windows Xp Edition embedded
   Microsoft ≫ Windows Xp Edition ibm_oem
   Microsoft ≫ Windows Xp Edition media_center
   Microsoft ≫ Windows Xp Edition pro
   Microsoft ≫ Windows Xp Edition tablet_pc
   Microsoft ≫ Windows Xp Edition x64
   Microsoft ≫ Windows Xp Version -
Novell ≫ Client Version 4.91 Update sp3
   Microsoft ≫ Windows 2000 Edition adv_srv
   Microsoft ≫ Windows 2000 Edition datacenter_srv
   Microsoft ≫ Windows 2000 Edition pro
   Microsoft ≫ Windows 2000 Edition srv
   Microsoft ≫ Windows 2000 Edition srv Lang ja
   Microsoft ≫ Windows 2000 Version -
   Microsoft ≫ Windows 2003 Server Edition itanium
   Microsoft ≫ Windows 2003 Server Edition std
   Microsoft ≫ Windows 2003 Server Edition wed
   Microsoft ≫ Windows 2003 Server Edition x64
   Microsoft ≫ Windows 2003 Server Edition x64-std
   Microsoft ≫ Windows 2003 Server Edition xp-64bit
   Microsoft ≫ Windows 2003 Server Version -
   Microsoft ≫ Windows Server 2003
   Microsoft ≫ Windows Xp Edition 64bit
   Microsoft ≫ Windows Xp Edition embedded
   Microsoft ≫ Windows Xp Edition ibm_oem
   Microsoft ≫ Windows Xp Edition media_center
   Microsoft ≫ Windows Xp Edition pro
   Microsoft ≫ Windows Xp Edition tablet_pc
   Microsoft ≫ Windows Xp Edition x64
   Microsoft ≫ Windows Xp Version -
Novell ≫ Client Version 4.91 Update sp4
   Microsoft ≫ Windows 2000 Edition adv_srv
   Microsoft ≫ Windows 2000 Edition datacenter_srv
   Microsoft ≫ Windows 2000 Edition pro
   Microsoft ≫ Windows 2000 Edition srv
   Microsoft ≫ Windows 2000 Edition srv Lang ja
   Microsoft ≫ Windows 2000 Version -
   Microsoft ≫ Windows 2003 Server Edition itanium
   Microsoft ≫ Windows 2003 Server Edition std
   Microsoft ≫ Windows 2003 Server Edition wed
   Microsoft ≫ Windows 2003 Server Edition x64
   Microsoft ≫ Windows 2003 Server Edition x64-std
   Microsoft ≫ Windows 2003 Server Edition xp-64bit
   Microsoft ≫ Windows 2003 Server Version -
   Microsoft ≫ Windows Server 2003
   Microsoft ≫ Windows Xp Edition 64bit
   Microsoft ≫ Windows Xp Edition embedded
   Microsoft ≫ Windows Xp Edition ibm_oem
   Microsoft ≫ Windows Xp Edition media_center
   Microsoft ≫ Windows Xp Edition pro
   Microsoft ≫ Windows Xp Edition tablet_pc
   Microsoft ≫ Windows Xp Edition x64
   Microsoft ≫ Windows Xp Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.282
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=626
http://osvdb.org/40867
http://secunia.com/advisories/27678
Patch
Vendor Advisory
http://www.securityfocus.com/bid/26420
http://www.securitytracker.com/id?1018943
http://www.vupen.com/english/advisories/2007/3846
https://exchange.xforce.ibmcloud.com/vulnerabilities/38434
https://secure-support.novell.com/KanisaPlatform/Publishing/98/3260263_f.SAL_Public.html
Patch