MEDIUM · 5.8

CVE-2007-4375

The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote a...

Vulnerability Description

The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.

CVSS Score

5.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:P
Confidentiality
PARTIAL
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
DiskeeperDiskeeper9

References

FAQ

What is CVE-2007-4375?

CVE-2007-4375 is a vulnerability with a CVSS score of 5.8 (MEDIUM). The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote a...

How severe is CVE-2007-4375?

CVE-2007-4375 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-4375?

Check the references section above for vendor advisories and patch information. Affected products include: Diskeeper Diskeeper.