Lucene search

K
cveMitreCVE-2008-5724
HistoryDec 26, 2008 - 5:30 p.m.

CVE-2008-5724

2008-12-2617:30:00
CWE-264
mitre
web.nvd.nist.gov
28
eset smart security
epfw.sys
privilege escalation
cve-2008-5724
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

High

EPSS

0

Percentile

0.4%

The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to \Device\Epfw that overwrites portions of memory.

Affected configurations

Nvd
Node
esetsmart_securityRange3.0.672
OR
esetsmart_securityMatch3.0.551
OR
esetsmart_securityMatch3.0.560
OR
esetsmart_securityMatch3.0.563
OR
esetsmart_securityMatch3.0.621
OR
esetsmart_securityMatch3.0.642
OR
esetsmart_securityMatch3.0.650
OR
esetsmart_securityMatch3.0.657
OR
esetsmart_securityMatch3.0.667
OR
esetsmart_securityMatch3.0.669
VendorProductVersionCPE
esetsmart_security*cpe:2.3:a:eset:smart_security:*:*:*:*:*:*:*:*
esetsmart_security3.0.551cpe:2.3:a:eset:smart_security:3.0.551:*:*:*:*:*:*:*
esetsmart_security3.0.560cpe:2.3:a:eset:smart_security:3.0.560:*:*:*:*:*:*:*
esetsmart_security3.0.563cpe:2.3:a:eset:smart_security:3.0.563:*:*:*:*:*:*:*
esetsmart_security3.0.621cpe:2.3:a:eset:smart_security:3.0.621:*:*:*:*:*:*:*
esetsmart_security3.0.642cpe:2.3:a:eset:smart_security:3.0.642:*:*:*:*:*:*:*
esetsmart_security3.0.650cpe:2.3:a:eset:smart_security:3.0.650:*:*:*:*:*:*:*
esetsmart_security3.0.657cpe:2.3:a:eset:smart_security:3.0.657:*:*:*:*:*:*:*
esetsmart_security3.0.667cpe:2.3:a:eset:smart_security:3.0.667:*:*:*:*:*:*:*
esetsmart_security3.0.669cpe:2.3:a:eset:smart_security:3.0.669:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

High

EPSS

0

Percentile

0.4%

Related for CVE-2008-5724