{"api_version":"1","generated_at":"2026-07-23T08:13:48+00:00","cve":"CVE-2004-2477","urls":{"html":"https://cve.report/CVE-2004-2477","api":"https://cve.report/api/cve/CVE-2004-2477.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2477","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2477"},"summary":{"title":"CVE-2004-2477","description":"DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \\device\\physicalmemory with the original SDT found in ntoskrnl.exe.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:P","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.security.org.sg/vuln/procguard.html","name":"http://www.security.org.sg/vuln/procguard.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SIG^2 G-TEC - DiamondCS Process Guard Can Be Disabled by Direct Service Table Restoration","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/7606","name":"http://www.osvdb.org/7606","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16654","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16654","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/alerts/2004/Jul/1010662.html","name":"http://www.securitytracker.com/alerts/2004/Jul/1010662.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SecurityTracker.com Archives - DiamondCS Process Guard Can Be Disabled By Local Users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/10675","name":"http://www.securityfocus.com/bid/10675","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"DiamondCS Process Guard Service Description Table Restoration Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/12033","name":"http://secunia.com/advisories/12033","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - DiamondCS Process Guard Protection Features Disabling Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2477","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2477","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2477","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"diamondcs","cpe5":"process_guard_free","cpe6":"2.000","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:29:13.670Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"10675","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/10675"},{"name":"diamondcs-process-guard-disable-protection(16654)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16654"},{"name":"7606","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/7606"},{"name":"12033","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12033"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.security.org.sg/vuln/procguard.html"},{"name":"1010662","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/alerts/2004/Jul/1010662.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-07-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \\device\\physicalmemory with the original SDT found in ntoskrnl.exe."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"10675","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/10675"},{"name":"diamondcs-process-guard-disable-protection(16654)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16654"},{"name":"7606","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/7606"},{"name":"12033","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12033"},{"tags":["x_refsource_MISC"],"url":"http://www.security.org.sg/vuln/procguard.html"},{"name":"1010662","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/alerts/2004/Jul/1010662.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2477","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \\device\\physicalmemory with the original SDT found in ntoskrnl.exe."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"10675","refsource":"BID","url":"http://www.securityfocus.com/bid/10675"},{"name":"diamondcs-process-guard-disable-protection(16654)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16654"},{"name":"7606","refsource":"OSVDB","url":"http://www.osvdb.org/7606"},{"name":"12033","refsource":"SECUNIA","url":"http://secunia.com/advisories/12033"},{"name":"http://www.security.org.sg/vuln/procguard.html","refsource":"MISC","url":"http://www.security.org.sg/vuln/procguard.html"},{"name":"1010662","refsource":"SECTRACK","url":"http://www.securitytracker.com/alerts/2004/Jul/1010662.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2477","datePublished":"2005-08-21T04:00:00.000Z","dateReserved":"2005-08-21T00:00:00.000Z","dateUpdated":"2024-08-08T01:29:13.670Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:P","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:diamondcs:process_guard_free:2.000:*:*:*:*:*:*:*","matchCriteriaId":"E360DE24-67C1-4AA1-8763-5B5F2DA14AB0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2477","Ordinal":"1","Title":"CVE-2004-2477","CVE":"CVE-2004-2477","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2477","Ordinal":"1","NoteData":"DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \\device\\physicalmemory with the original SDT found in ntoskrnl.exe.","Type":"Description","Title":"CVE-2004-2477"},{"CveYear":"2004","CveId":"2477","Ordinal":"2","NoteData":"2005-08-21","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2477","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}