CVE-2007-5047

Norton Internet Security 2008 15.0.0.60 - Denial of Service via NtOpenSection SSDT Hook

Title source: llm
STIX 2.1

Description

Norton Internet Security 2008 15.0.0.60 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the NtOpenSection kernel SSDT hook. NOTE: the NtCreateMutant and NtOpenEvent function hooks are already covered by CVE-2007-1793.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/45897
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3161
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/479830/100/0/threaded

Scores

EPSS 0.0006
EPSS Percentile 18.2%

Details

CWE
CWE-20
Status published
Products (1)
symantec/norton_internet_security 2008_15.0.0.60
Published Sep 24, 2007
Tracked Since Feb 18, 2026