PoC Index

CVE-2007-1793

MEDIUM 4.9EPSS 1.7%

SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions. NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected.

CVSS v2.0
4.9 MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
EPSS
1.72% chance of exploitation in the next 30 days, 76th percentile
Published
2007-04-02
Updated
2024-08-07

ExploitDB entries (1)

References

Related