Vulnerabilities > CVE-2007-3673 - Local Privilege Escalation vulnerability in Symantec Device Driver SYMTDI.SYS
Attack vector
LOCAL Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE local
symantec
Summary
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\symTDI\, which results in memory overwrite.
Vulnerable Configurations
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=554
- http://osvdb.org/36117
- http://secunia.com/advisories/26042
- http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11d.html
- http://securitytracker.com/id?1018372
- http://www.securityfocus.com/bid/22351
- http://www.vupen.com/english/advisories/2007/2507
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35347