Vulnerabilities > CVE-2007-2083 - Unspecified vulnerability in Zonelabs Zonealarm

047910
CVSS 6.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
zonelabs
exploit available

Summary

vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateKey and (2) NtDeleteFile functions.

Vulnerable Configurations

Part Description Count
Application
Zonelabs
1

Exploit-Db

descriptionZoneAlarm 6.1.744.001/6.5.737.000 Vsdatant.SYS Driver Local Denial of Service Vulnerability. CVE-2007-2083. Dos exploit for windows platform
idEDB-ID:29860
last seen2016-02-03
modified2007-04-15
published2007-04-15
reporterMatousec Transparent security
sourcehttps://www.exploit-db.com/download/29860/
titleZoneAlarm 6.1.744.001/6.5.737.000 Vsdatant.SYS Driver Local Denial of Service Vulnerability