HIGH · 7.2

CVE-2009-2450

The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Personal Firewall 3.5 before 3.5.0.14, allows local users to gain privileges via cra...

Vulnerability Description

The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Personal Firewall 3.5 before 3.5.0.14, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\OAmon containing arbitrary kernel addresses, as demonstrated using the 0x830020C3 IOCTL.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
TallemuOnline Armor Personal Firewall Av\+<= 3.5.0.11
TallemuPersonal Firewall<= 3.5.0.13

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2450?

CVE-2009-2450 is a vulnerability with a CVSS score of 7.2 (HIGH). The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Personal Firewall 3.5 before 3.5.0.14, allows local users to gain privileges via cra...

How severe is CVE-2009-2450?

CVE-2009-2450 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2450?

Check the references section above for vendor advisories and patch information. Affected products include: Tallemu Online Armor Personal Firewall Av\+, Tallemu Personal Firewall.