Vulnerability CVE-2004-2477


Published: 2004-12-31   Modified: 2012-02-12

Description:
DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe.

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Diamondcs -> Process guard free 

 References:
http://xforce.iss.net/xforce/xfdb/16654
http://www.securitytracker.com/alerts/2004/Jul/1010662.html
http://www.securityfocus.com/bid/10675
http://www.security.org.sg/vuln/procguard.html
http://www.osvdb.org/7606
http://secunia.com/advisories/12033

Copyright 2024, cxsecurity.com

 

Back to Top