CVE-2007-5587
Macrovision SafeDisc - 'SecDRV.SYS' Method_Neither Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.
Un desbordamiento de búfer en Macrovision SafeDisc secdrv.sys versiones anteriores a 4.3.86.0, tal y como se incorporó en Microsoft Windows XP SP2, XP Professional x64 y x64 SP2, Server 2003 SP1 y SP2, y Server 2003 x64 y x64 SP2 permite a usuarios locales sobrescribir ubicaciones arbitrarias de memoria y alcanzar privilegios por medio de un argumento diseñado para un METHOD_NEITHER IOCTL, como se detectó originalmente “in the wild”.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-10-18 First Exploit
- 2007-10-19 CVE Reserved
- 2007-10-19 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://osvdb.org/41429 | Vdb Entry | |
http://secunia.com/advisories/27285 | Third Party Advisory | |
http://securityreason.com/securityalert/3266 | Third Party Advisory | |
http://www.reversemode.com/index.php?option=com_mamblog&Itemid=15&task=show&action=view&id=43&Itemid=15 | X_refsource_misc | |
http://www.securityfocus.com/archive/1/482474/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/482482/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/26121 | Vdb Entry | |
http://www.securitytracker.com/id?1018833 | Vdb Entry | |
http://www.symantec.com/enterprise/security_response/weblog/2007/10/privilege_escalation_exploit_i.html | X_refsource_misc | |
http://www.us-cert.gov/cas/techalerts/TA07-345A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2007/3537 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37284 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4584 | Signature |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/30680 | 2007-10-18 | |
http://blog.48bits.com/?p=172 | 2024-08-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Macrovision Search vendor "Macrovision" | Safedisc Search vendor "Macrovision" for product "Safedisc" | * | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | * | - |
Safe
|
Macrovision Search vendor "Macrovision" | Safedisc Search vendor "Macrovision" for product "Safedisc" | * | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | - |
Safe
|