CVE-2003-1309
Summary
| CVE | CVE-2003-1309 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-12-31 05:00:00 UTC |
| Updated | 2017-07-29 01:29:00 UTC |
| Description | The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack"). |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zonelabs | Zonealarm | 3.7.202 | All | All | All |
| Application | Zonelabs | Zonealarm | 3.7.211 | All | plus | All |
| Application | Zonelabs | Zonealarm | 3.7.211 | All | pro | All |
| Application | Zonelabs | Zonealarm | 3.7.202 | All | All | All |
| Application | Zonelabs | Zonealarm | 3.7.211 | All | plus | All |
| Application | Zonelabs | Zonealarm | 3.7.211 | All | pro | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2375 | OSVDB | www.osvdb.org | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| [sec-labs] Win32 Device Communication Vulnerabilities | MISC | sec-labs.hack.pl | |
| Strona nie znaleziona - hack.pl | MISC | sec-labs.hack.pl | |
| Secunia - Advisories - ZoneAlarm TrueVector Device Driver Privilege Escalation | SECUNIA | secunia.com | Patch, Vendor Advisory |
| ZoneAlarm Local Device Driver IO Control Code Execution Vulnerability | BID | www.securityfocus.com | Vendor Advisory |
| Neohapsis Archives - VulnWatch - #0070 - [VulnWatch] Local ZoneAlarm Firewall (probably all versions - tested on v3.1) | VULNWATCH | archives.neohapsis.com | Exploit, Vendor Advisory |
| 4362 | OSVDB | www.osvdb.org | Patch, Vendor Advisory |
| Zone Labs: ZoneAlarm Release History | CONFIRM | download.zonelabs.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.