CVE-2008-5724

The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to DeviceEpfw that overwrites portions of memory.
Configurations

Configuration 1

cpe:2.3:a:eset:smart_security:3.0.669:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:*:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.657:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.650:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.621:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.560:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.642:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.551:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.563:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:3.0.667:*:*:*:*:*:*:*

Information

Published : 2008-12-26 05:30

Updated : 2017-08-08 01:33


NVD link : CVE-2008-5724

Mitre link : CVE-2008-5724

Products Affected
CWE
CWE-781

Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code