7.2

CVE-2007-5667

NWFILTER.SYS in Novell Client 4.91 SP 1 through SP 4 for Windows 2000, XP, and Server 2003 makes the \.\nwfilter device available for arbitrary user-mode input via METHOD_NEITHER IOCTLs, which allows local users to gain privileges by passing a kernel address as an argument and overwriting kernel memory locations.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NovellClient Version4.91 Updatesp1
   MicrosoftWindows 2000 Editionadv_srv
   MicrosoftWindows 2000 Editiondatacenter_srv
   MicrosoftWindows 2000 Editionpro
   MicrosoftWindows 2000 Editionsrv
   MicrosoftWindows 2000 Editionsrv Langja
   MicrosoftWindows 2000 Version-
   MicrosoftWindows 2003 Server Editionitanium
   MicrosoftWindows 2003 Server Editionstd
   MicrosoftWindows 2003 Server Editionwed
   MicrosoftWindows 2003 Server Editionx64
   MicrosoftWindows 2003 Server Editionx64-std
   MicrosoftWindows 2003 Server Editionxp-64bit
   MicrosoftWindows 2003 Server Version-
   MicrosoftWindows Server 2003
   MicrosoftWindows Xp Edition64bit
   MicrosoftWindows Xp Editionembedded
   MicrosoftWindows Xp Editionibm_oem
   MicrosoftWindows Xp Editionmedia_center
   MicrosoftWindows Xp Editionpro
   MicrosoftWindows Xp Editiontablet_pc
   MicrosoftWindows Xp Editionx64
   MicrosoftWindows Xp Version-
NovellClient Version4.91 Updatesp2
   MicrosoftWindows 2000 Editionadv_srv
   MicrosoftWindows 2000 Editiondatacenter_srv
   MicrosoftWindows 2000 Editionpro
   MicrosoftWindows 2000 Editionsrv
   MicrosoftWindows 2000 Editionsrv Langja
   MicrosoftWindows 2000 Version-
   MicrosoftWindows 2003 Server Editionitanium
   MicrosoftWindows 2003 Server Editionstd
   MicrosoftWindows 2003 Server Editionwed
   MicrosoftWindows 2003 Server Editionx64
   MicrosoftWindows 2003 Server Editionx64-std
   MicrosoftWindows 2003 Server Editionxp-64bit
   MicrosoftWindows 2003 Server Version-
   MicrosoftWindows Server 2003
   MicrosoftWindows Xp Edition64bit
   MicrosoftWindows Xp Editionembedded
   MicrosoftWindows Xp Editionibm_oem
   MicrosoftWindows Xp Editionmedia_center
   MicrosoftWindows Xp Editionpro
   MicrosoftWindows Xp Editiontablet_pc
   MicrosoftWindows Xp Editionx64
   MicrosoftWindows Xp Version-
NovellClient Version4.91 Updatesp3
   MicrosoftWindows 2000 Editionadv_srv
   MicrosoftWindows 2000 Editiondatacenter_srv
   MicrosoftWindows 2000 Editionpro
   MicrosoftWindows 2000 Editionsrv
   MicrosoftWindows 2000 Editionsrv Langja
   MicrosoftWindows 2000 Version-
   MicrosoftWindows 2003 Server Editionitanium
   MicrosoftWindows 2003 Server Editionstd
   MicrosoftWindows 2003 Server Editionwed
   MicrosoftWindows 2003 Server Editionx64
   MicrosoftWindows 2003 Server Editionx64-std
   MicrosoftWindows 2003 Server Editionxp-64bit
   MicrosoftWindows 2003 Server Version-
   MicrosoftWindows Server 2003
   MicrosoftWindows Xp Edition64bit
   MicrosoftWindows Xp Editionembedded
   MicrosoftWindows Xp Editionibm_oem
   MicrosoftWindows Xp Editionmedia_center
   MicrosoftWindows Xp Editionpro
   MicrosoftWindows Xp Editiontablet_pc
   MicrosoftWindows Xp Editionx64
   MicrosoftWindows Xp Version-
NovellClient Version4.91 Updatesp4
   MicrosoftWindows 2000 Editionadv_srv
   MicrosoftWindows 2000 Editiondatacenter_srv
   MicrosoftWindows 2000 Editionpro
   MicrosoftWindows 2000 Editionsrv
   MicrosoftWindows 2000 Editionsrv Langja
   MicrosoftWindows 2000 Version-
   MicrosoftWindows 2003 Server Editionitanium
   MicrosoftWindows 2003 Server Editionstd
   MicrosoftWindows 2003 Server Editionwed
   MicrosoftWindows 2003 Server Editionx64
   MicrosoftWindows 2003 Server Editionx64-std
   MicrosoftWindows 2003 Server Editionxp-64bit
   MicrosoftWindows 2003 Server Version-
   MicrosoftWindows Server 2003
   MicrosoftWindows Xp Edition64bit
   MicrosoftWindows Xp Editionembedded
   MicrosoftWindows Xp Editionibm_oem
   MicrosoftWindows Xp Editionmedia_center
   MicrosoftWindows Xp Editionpro
   MicrosoftWindows Xp Editiontablet_pc
   MicrosoftWindows Xp Editionx64
   MicrosoftWindows Xp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.091
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.