CVE-2007-4648

N/A Unknown
Published: August 31, 2007 Modified: April 23, 2026
View on NVD

Description

The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa device, which allows local users to gain privileges by (1) triggering a buffer overflow in a kernel pool via a string argument to ioctl 0xBF67201C; or by (2) sending a crafted KEVENT structure through ioctl 0xBF672028 to overwrite arbitrary memory locations.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.48bits.com/exploits/nvc.rar
Source: cve@mitre.org
Exploit
http://securityreason.com/securityalert/3087
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.48bits.com/exploits/nvc.rar
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.securityfocus.com/archive/1/478224/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/25499
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1018636
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/36373
Source: af854a3a-2127-422b-91ae-364da2661108

12 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.9%
56th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

norman