Local Privilege Escalation in Symantec AntiVirus and Related Products
CVE-2007-3673

Currently unrated

Key Information:

Vendor

Symantec

Vendor
CVE Published:
15 July 2007

What is CVE-2007-3673?

The vulnerability lies within the symtdi.sys driver in several Symantec products, where a malformed Interrupt Request Packet (IRP) in an IOCTL 0x83022323 request can lead to unauthorized local privilege escalation. This allows local users to gain elevated privileges and potentially modify system settings or access sensitive data, posing significant security risks for affected systems. Users are encouraged to update their software to the latest versions to mitigate these risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.