MEDIUM · 6.9

CVE-2007-3673

Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Securi...

Vulnerability Description

Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\symTDI\, which results in memory overwrite.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SymantecClient Security2.0
SymantecNorton Antispam2005
SymantecNorton Antivirus9.0
SymantecNorton Internet Security2005
SymantecNorton Personal Firewall2005
SymantecNorton System Works2005

References

FAQ

What is CVE-2007-3673?

CVE-2007-3673 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Securi...

How severe is CVE-2007-3673?

CVE-2007-3673 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3673?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Client Security, Symantec Norton Antispam, Symantec Norton Antivirus, Symantec Norton Internet Security, Symantec Norton Personal Firewall.