CVE-2003-1309
Summary
| CVE | CVE-2003-1309 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack"). |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/4362 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Patch, Vendor Advisory |
| ZoneAlarm Local Device Driver IO Control Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| Secunia - Advisories - ZoneAlarm TrueVector Device Driver Privilege Escalation | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Strona nie znaleziona - hack.pl | af854a3a-2127-422b-91ae-364da2661108 | sec-labs.hack.pl | |
| [sec-labs] Win32 Device Communication Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | sec-labs.hack.pl | |
| Neohapsis Archives - VulnWatch - #0070 - [VulnWatch] Local ZoneAlarm Firewall (probably all versions - tested on v3.1) | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit, Vendor Advisory |
| www.osvdb.org/2375 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Zone Labs: ZoneAlarm Release History | af854a3a-2127-422b-91ae-364da2661108 | download.zonelabs.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.