Vulnerability Details CVE-2007-3673
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\symTDI\, which results in memory overwrite.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.3%
CVSS Severity
CVSS v2 Score 6.9
Products affected by CVE-2007-3673
-
cpe:2.3:a:symantec:client_security:2.0
-
cpe:2.3:a:symantec:client_security:3.0
-
cpe:2.3:a:symantec:client_security:3.1
-
cpe:2.3:a:symantec:norton_antispam:2005
-
cpe:2.3:a:symantec:norton_antivirus:10.0
-
cpe:2.3:a:symantec:norton_antivirus:10.1
-
cpe:2.3:a:symantec:norton_antivirus:2005
-
cpe:2.3:a:symantec:norton_antivirus:2006
-
cpe:2.3:a:symantec:norton_antivirus:9.0
-
cpe:2.3:a:symantec:norton_antivirus:9.0.0.338
-
cpe:2.3:a:symantec:norton_antivirus:9.0.1
-
cpe:2.3:a:symantec:norton_antivirus:9.0.1.1.1000
-
cpe:2.3:a:symantec:norton_antivirus:9.0.1.1000
-
cpe:2.3:a:symantec:norton_antivirus:9.0.2
-
cpe:2.3:a:symantec:norton_antivirus:9.0.2.1000
-
cpe:2.3:a:symantec:norton_antivirus:9.0.3.1000
-
cpe:2.3:a:symantec:norton_antivirus:9.0.4
-
cpe:2.3:a:symantec:norton_antivirus:9.0.5
-
cpe:2.3:a:symantec:norton_antivirus:9.0.5.1100
-
cpe:2.3:a:symantec:norton_internet_security:2005
-
cpe:2.3:a:symantec:norton_internet_security:2006
-
cpe:2.3:a:symantec:norton_personal_firewall:2005
-
cpe:2.3:a:symantec:norton_personal_firewall:2006
-
cpe:2.3:a:symantec:norton_system_works:2005
-
cpe:2.3:a:symantec:norton_system_works:2006