CVE-2007-5042 Information
Feb 14, 2021
cve
Description
Outpost Firewall Pro 4.0.1025.7828 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey (2) NtDeleteFile (3) NtLoadDriver (4) NtOpenProcess (5) NtOpenSection (6) NtOpenThread and (7) NtUnloadDriver kernel SSDT hooks a partial regression of CVE-2006-7160.
Reference
http://osvdb.org/45899 http://securityreason.com/securityalert/3161 http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php http://www.securityfocus.com/archive/1/479830/100/0/threaded
Share on: