RSS   Vulnerabilities for 'Prosecurity'   RSS

2007-09-18
 
CVE-2007-4971

CWE-20
 

 
ProSecurity 1.40 Beta 2 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2) NtDeleteFile, (3) NtLoadDriver, (4) NtOpenSection, and (5) NtSetSystemTime.

 

 >>> Vendor: Isecsoft 3 Products
Prosecurity
Anti-trojan elite
Anti-keylogger elite


Copyright 2024, cxsecurity.com

 

Back to Top