Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-5724. PoCs published by NT Internals.
AI-analyzed exploit summary This exploit targets a local privilege escalation vulnerability in the ESET Personal Firewall driver (epfw.sys) due to improper input validation. It allows an attacker to escalate privileges by sending crafted IOCTL requests to the driver.
Description
The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to \Device\Epfw that overwrites portions of memory.
Exploits (1)
This exploit targets a local privilege escalation vulnerability in the ESET Personal Firewall driver (epfw.sys) due to improper input validation. It allows an attacker to escalate privileges by sending crafted IOCTL requests to the driver.