Insufficient Argument Validation in Symantec Norton Personal Firewall
CVE-2007-1793
Currently unrated
Key Information:
- Vendor
Symantec
- Vendor
- CVE Published:
- 2 April 2007
What is CVE-2007-1793?
The SPBBCDrv.sys driver in Symantec Norton Personal Firewall 2006 does not properly validate specific arguments before passing them to hooked SSDT function handlers. This flaw may allow local users to instigate a denial of service through system crashes or potentially execute arbitrary code via crafted input to the NtCreateMutant and NtOpenEvent functions. Reports indicate that Norton Internet Security 2008 and earlier versions could also be vulnerable to this issue.
References
Timeline
Vulnerability published
Vulnerability Reserved