gsd-2007-2174
Vulnerability from gsd
Modified
2023-12-13 01:21
Details
The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2007-2174", "description": "The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses.", "id": "GSD-2007-2174" }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2007-2174" ], "details": "The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses.", "id": "GSD-2007-2174", "modified": "2023-12-13T01:21:37.535231Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2007-2174", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "20070420 Check Point Zone Labs SRESCAN IOCTL Local Privilege Escalation Vulnerability", "refsource": "IDEFENSE", "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=517" }, { "name": "24986", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/24986" }, { "name": "ADV-2007-1491", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2007/1491" }, { "name": "1017953", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1017953" }, { "name": "23579", "refsource": "BID", "url": "http://www.securityfocus.com/bid/23579" }, { "name": "20070423 [Reversemode advisory] CheckPoint Zonelabs - ZoneAlarm SRESCAN driver local privilege escalation", "refsource": "BUGTRAQ", "url": "http://www.securityfocus.com/archive/1/466656/100/0/threaded" }, { "name": "zonealarm-srescan-privilege-escalation(33786)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33786" }, { "name": "1017948", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1017948" } ] } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:checkpoint:zonealarm:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndIncluding": "5.0.63.0", "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2007-2174" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ] }, "references": { "reference_data": [ { "name": "20070420 Check Point Zone Labs SRESCAN IOCTL Local Privilege Escalation Vulnerability", "refsource": "IDEFENSE", "tags": [ "Vendor Advisory" ], "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=517" }, { "name": "23579", "refsource": "BID", "tags": [], "url": "http://www.securityfocus.com/bid/23579" }, { "name": "1017948", "refsource": "SECTRACK", "tags": [], "url": "http://www.securitytracker.com/id?1017948" }, { "name": "24986", "refsource": "SECUNIA", "tags": [ "Patch", "Vendor Advisory" ], "url": "http://secunia.com/advisories/24986" }, { "name": "1017953", "refsource": "SECTRACK", "tags": [], "url": "http://www.securitytracker.com/id?1017953" }, { "name": "ADV-2007-1491", "refsource": "VUPEN", "tags": [], "url": "http://www.vupen.com/english/advisories/2007/1491" }, { "name": "zonealarm-srescan-privilege-escalation(33786)", "refsource": "XF", "tags": [], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33786" }, { "name": "20070423 [Reversemode advisory] CheckPoint Zonelabs - ZoneAlarm SRESCAN driver local privilege escalation", "refsource": "BUGTRAQ", "tags": [], "url": "http://www.securityfocus.com/archive/1/466656/100/0/threaded" } ] } }, "impact": { "baseMetricV2": { "cvssV2": { "accessComplexity": "LOW", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 7.2, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "version": "2.0" }, "exploitabilityScore": 3.9, "impactScore": 10.0, "obtainAllPrivilege": true, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "HIGH", "userInteractionRequired": false } }, "lastModifiedDate": "2018-10-16T16:42Z", "publishedDate": "2007-04-24T16:19Z" } } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…