CVE-2007-3673
Last modified
CVE-2007-3673 is a vulnerability of currently unknown severity. Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\symTDI\, which results in memory overwrite.. EPSS estimates a 1.06% chance of exploitation in the next 30 days.
Description
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\symTDI\, which results in memory overwrite.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Client Security | 2.0 |
| Symantec | Client Security | 3.0 |
| Symantec | Client Security | 3.1 |
| Symantec | Norton Antispam | 2005 |
| Symantec | Norton Antivirus | 9.0 |
| Symantec | Norton Antivirus | 9.0.0.338 |
| Symantec | Norton Antivirus | 9.0.1 |
| Symantec | Norton Antivirus | 9.0.1.1.1000 |
| Symantec | Norton Antivirus | 9.0.1.1000 |
| Symantec | Norton Antivirus | 9.0.2 |
| Symantec | Norton Antivirus | 9.0.2.1000 |
| Symantec | Norton Antivirus | 9.0.3.1000 |
| Symantec | Norton Antivirus | 9.0.4 |
| Symantec | Norton Antivirus | 9.0.5 |
| Symantec | Norton Antivirus | 9.0.5.1100 |
| Symantec | Norton Antivirus | 10.0 |
| Symantec | Norton Antivirus | 10.1 |
| Symantec | Norton Antivirus | 2005 |
| Symantec | Norton Antivirus | 2006 |
| Symantec | Norton Internet Security | 2005 |
| Symantec | Norton Internet Security | 2006 |
| Symantec | Norton Personal Firewall | 2005 |
| Symantec | Norton Personal Firewall | 2006 |
| Symantec | Norton System Works | 2005 |
| Symantec | Norton System Works | 2006 |
References
- http://secunia.com/advisories/26042Vendor Advisory
- http://secunia.com/advisories/26042Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3673?
How severe is CVE-2007-3673?
How do I fix CVE-2007-3673?
Are you affected by CVE-2007-3673?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
