CVE-2007-4375
Last modified
CVE-2007-4375 is a vulnerability of currently unknown severity. The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.. EPSS estimates a 3.38% chance of exploitation in the next 30 days.
Description
The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Diskeeper | Diskeeper | 9 |
| Diskeeper | Diskeeper | 2007 |
References
- http://secunia.com/advisories/26431Vendor Advisory
- http://secunia.com/advisories/26431Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4375?
How severe is CVE-2007-4375?
How do I fix CVE-2007-4375?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4369Directory traversal vulnerability in go/_files in SOTEeSKLEP…
- CVE-2007-4370Multiple buffer overflows in the (1) client and (2) server i…
- CVE-2007-4371Unrestricted file upload vulnerability in admin/pages/blog-a…
- CVE-2007-4372Unspecified vulnerability in NetWin SurgeMail 38k on Windows…
- CVE-2007-4373The server in Babo Violent 2 2.08.00 and earlier does not pr…
- CVE-2007-4374Babo Violent 2 2.08.00 does not validate the sender field of…
- CVE-2007-4376Unrestricted file upload vulnerability in banner-upload.php …
- CVE-2007-4377Stack-based buffer overflow in the IMAP service in SurgeMail…
- CVE-2007-4378Multiple format string vulnerabilities in Babo Violent 2 2.0…
- CVE-2007-4379Babo Violent 2 2.08.00 and earlier allows remote attackers t…
- CVE-2007-4380Aclient in Symantec Altiris Deployment Solution 6 before 6.8…
- CVE-2007-4381Unspecified vulnerability in the font parsing implementation…
Are you affected by CVE-2007-4375?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
