CVE-2008-5724

The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to \Device\Epfw that overwrites portions of memory.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eset:smart_security:*:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.551:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.560:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.563:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.621:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.642:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.650:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.657:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.667:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.669:*:*:*:*:*:*:*

History

21 Nov 2024, 00:54

Type Values Removed Values Added
References () http://secunia.com/advisories/33210 - Vendor Advisory () http://secunia.com/advisories/33210 - Vendor Advisory
References () http://www.eset.com/joomla/index.php?option=com_content&task=view&id=4113&Itemid=5 - () http://www.eset.com/joomla/index.php?option=com_content&task=view&id=4113&Itemid=5 -
References () http://www.ntinternals.org/ntiadv0807/ntiadv0807.html - () http://www.ntinternals.org/ntiadv0807/ntiadv0807.html -
References () http://www.securityfocus.com/bid/32917 - () http://www.securityfocus.com/bid/32917 -
References () http://www.vupen.com/english/advisories/2008/3456 - () http://www.vupen.com/english/advisories/2008/3456 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/47477 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/47477 -

Information

Published : 2008-12-26 17:30

Updated : 2024-11-21 00:54


NVD link : CVE-2008-5724

Mitre link : CVE-2008-5724

CVE.ORG link : CVE-2008-5724


JSON object : View

Products Affected

eset

  • smart_security
CWE
CWE-264

Permissions, Privileges, and Access Controls