The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to \Device\Epfw that overwrites portions of memory.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.eset.com/joomla/index.php?option=com_content&task=view&id=4113&Itemid=5 | |
http://secunia.com/advisories/33210 | third party advisory vendor advisory |
http://www.ntinternals.org/ntiadv0807/ntiadv0807.html | |
http://www.vupen.com/english/advisories/2008/3456 | vdb entry |
http://www.securityfocus.com/bid/32917 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/47477 | vdb entry |