CVE-2007-3673
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/07/2007
Last modified:
09/04/2025
Description
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\symTDI\, which results in memory overwrite.
Impact
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:symantec:client_security:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:client_security:3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:client_security:3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antispam:2005:*:*:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0:*:corporate:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.0.338:*:corporate:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.1:*:corporate:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.1.1.1000:*:corporate:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.1.1000:*:corporate:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.2:*:corporate:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.2.1000:*:corporate:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.3.1000:*:corporate:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.4:*:corporate:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.5:*:corporate:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.5.1100:*:corporate:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=554
- http://osvdb.org/36117
- http://secunia.com/advisories/26042
- http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11d.html
- http://securitytracker.com/id?1018372=
- http://www.securityfocus.com/bid/22351
- http://www.vupen.com/english/advisories/2007/2507
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35347
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=554
- http://osvdb.org/36117
- http://secunia.com/advisories/26042
- http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11d.html
- http://securitytracker.com/id?1018372=
- http://www.securityfocus.com/bid/22351
- http://www.vupen.com/english/advisories/2007/2507
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35347



