3087Third-party advisory
http://securityreason.com/securityalert/3087 CVE-2007-4648
Norman Virus Control - 'nvcoaft51.sys' ioctl BF672028
Record summary
CVE-2007-4648 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa device, which allows local users to gain privileges by (1) triggering a buffer overflow in a kernel pool via a string argument to ioctl 0xBF67201C; or by (2) sending a crafted KEVENT structure through ioctl 0xBF672028 to overwrite arbitrary memory locations.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNorman Virus Control - 'nvcoaft51.sys' ioctl BF672028ExploitDB exploitby inocraMNot analyzed1 file
References
748bits.com
http://www.48bits.com/exploits/nvc.rar 20070830 [48bits] Advisory : Multiple vulnerabilities in Norman NVC 5.82 drivermailing list
http://www.securityfocus.com/archive/1/478224/100/0/threaded 25499vdb entry
http://www.securityfocus.com/bid/25499 1018636vdb entry
http://www.securitytracker.com/id?1018636 norman-nvcoaft-privilege-escalation(36373)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/36373 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4648