CVE-2007-5047
Norton Internet Security 2008 15.0.0.60 - Denial of Service via NtOpenSection SSDT Hook
Title source: llmDescription
Norton Internet Security 2008 15.0.0.60 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the NtOpenSection kernel SSDT hook. NOTE: the NtCreateMutant and NtOpenEvent function hooks are already covered by CVE-2007-1793.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_misc
http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php
Vendor Advisory x_refsource_misc
http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/45897
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/3161
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/479830/100/0/threaded
Scores
EPSS
0.0006
EPSS Percentile
18.2%
Details
CWE
CWE-20
Status
published
Products (1)
symantec/norton_internet_security
2008_15.0.0.60
Published
Sep 24, 2007
Tracked Since
Feb 18, 2026