cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.16.174 and earlier does not validate arguments that originate in user mode for the (1) NtCreateSection, (2) NtOpenProcess, (3) NtOpenSection, (4) NtOpenThread, and (5) NtSetValueKey hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.
References
Configurations
History
21 Nov 2024, 00:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://securitytracker.com/id?1017580 - | |
References | () http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/458773/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/22357 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/32059 - |
Information
Published : 2007-02-04 00:28
Updated : 2024-11-21 00:26
NVD link : CVE-2007-0709
Mitre link : CVE-2007-0709
CVE.ORG link : CVE-2007-0709
JSON object : View
Products Affected
comodo
- comodo_firewall_pro
CWE