Record summary

CVE-2007-4648 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.

Description

The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa device, which allows local users to gain privileges by (1) triggering a buffer overflow in a kernel pool via a string argument to ioctl 0xBF67201C; or by (2) sending a crafted KEVENT structure through ioctl 0xBF672028 to overwrite arbitrary memory locations.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBNorman Virus Control - 'nvcoaft51.sys' ioctl BF672028ExploitDB exploitby inocraMNot analyzed1 file
ExploitDB

PoC details

References

7