Vulnerability CVE-2007-5762


Published: 2008-01-09   Modified: 2012-02-12

Description:
NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Novell Client 4.91 SP3/4 Privilege Escalation
sickness
23.05.2012

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Novell -> Netware client 

 References:
http://www.securityfocus.com/bid/27209
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=637
http://download.novell.com/Download?buildid=4FmI89wOmg4
~
http://xforce.iss.net/xforce/xfdb/39576
http://www.vupen.com/english/advisories/2008/0088
http://www.securitytracker.com/id?1019172
http://secunia.com/advisories/28396

Copyright 2024, cxsecurity.com

 

Back to Top