Vulnerability Name:

CVE-2007-4216 (CCN-36107)

Assigned:2007-08-20
Published:2007-08-20
Updated:2018-10-15
Summary:vsdatant.sys 6.5.737.0 in Check Point Zone Labs ZoneAlarm before 7.0.362 allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in a METHOD_NEITHER (1) IOCTL 0x8400000F or (2) IOCTL 0x84000013 request, which can be used to overwrite arbitrary memory locations.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-20
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: BugTraq Mailing List, Mon Aug 20 2007 - 11:56:34 CDT
CheckPoint ZoneLabs Vsdatant.sys multiple local privilege escalation vulnerabilities

Source: MITRE
Type: CNA
CVE-2007-4216

Source: IDEFENSE
Type: UNKNOWN
20070820 Check Point Zone Labs VSDATANT Multiple IOCTL Privilege Escalation Vulnerabilities

Source: CCN
Type: SA26513
ZoneAlarm Products Insecure Directory Permissions and IOCTL Handler Privilege Escalation

Source: SECUNIA
Type: UNKNOWN
26513

Source: CCN
Type: SECTRACK ID: 1018589
ZoneAlarm IOCTL Validation Flaw Lets Local Users Gain Elevated Privileges

Source: SECTRACK
Type: UNKNOWN
1018589

Source: CCN
Type: OSVDB ID: 37384
ZoneAlarm vsdatant.sys Interrupt Request Packet (Irp) METHOD_NEITHER Request Remote Privilege Escalation

Source: MISC
Type: UNKNOWN
http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=53

Source: BUGTRAQ
Type: UNKNOWN
20070820 [Reversemode Advisory] CheckPoint ZoneLabs Vsdatant.sys multiple local privilege escalation vulnerabilities

Source: BID
Type: UNKNOWN
25365

Source: CCN
Type: BID-25365
Check Point Zone Labs Multiple Products Local Privilege Escalation Vulnerabilities

Source: BID
Type: UNKNOWN
25377

Source: CCN
Type: BID-25377
RETIRED: Check Point ZoneAlarm Multiple Products Local Privilege Escalation Vulnerabilities

Source: VUPEN
Type: Vendor Advisory
ADV-2007-2929

Source: CCN
Type: Check Point ZoneAlarm Service and Support Web site
ZoneAlarm by Check Point - Award winning PC Protection, Antivirus, Firewall, Anti-Spyware, Identity Protection, and much more.

Source: XF
Type: UNKNOWN
zonealarm-vsdatant-privilege-escalation(36107)

Source: XF
Type: UNKNOWN
zonealarm-vsdatant-privilege-escalation(36107)

Source: CCN
Type: iDefense Labs PUBLIC ADVISORY: 08.20.07
Check Point Zone Labs VSDATANT Multiple IOCTL Privilege Escalation Vulnerabilities

Vulnerable Configuration:Configuration 1:
  • cpe:/a:checkpoint:zonealarm:5.0.63.0:*:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:zonealarm:6.1.744.001:*:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:zonealarm:*:*:*:*:*:*:*:* (Version <= 7.0.337.0)

  • Configuration CCN 1:
  • cpe:/a:checkpoint:zonealarm:7.0.337.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    checkpoint zonealarm 5.0.63.0
    checkpoint zonealarm 6.1.744.001
    checkpoint zonealarm *
    checkpoint zonealarm 7.0.337.0