LOW · 1.9

CVE-2007-4972

RegMon 7.04 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain p...

Vulnerability Description

RegMon 7.04 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks to the (1) NtCreateKey and (2) NtOpenKey Windows Native API functions.

CVSS Score

1.9

LOW

AV:L/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
SysinternalsRegmon7.04

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-4972?

CVE-2007-4972 is a vulnerability with a CVSS score of 1.9 (LOW). RegMon 7.04 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain p...

How severe is CVE-2007-4972?

CVE-2007-4972 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-4972?

Check the references section above for vendor advisories and patch information. Affected products include: Sysinternals Regmon.