CVE-2008-1471

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
24/03/2008
Last modified:
09/04/2025

Description

The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microsoft:windows-nt:vista:*:x32:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:*:x32:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:*:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:x64:*:*:*:*:*
cpe:2.3:a:panda:panda_antivirus_and_firewall:2008:*:*:*:*:*:*:*
cpe:2.3:a:panda:panda_internet_security:2008:*:*:*:*:*:*:*