CVE-2007-5040 Information
Feb 14, 2021
cve
Description
Ghost Security Suite alpha 1.200 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey (2) NtCreateThread (3) NtDeleteValueKey (4) NtQueryValueKey (5) NtSetSystemInformation and (6) NtSetValueKey kernel SSDT hooks.
Reference
http://securityreason.com/securityalert/3161 http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php http://www.securityfocus.com/archive/1/479830/100/0/threaded
Share on: