{"api_version":"1","generated_at":"2026-07-23T09:29:11+00:00","cve":"CVE-2007-4970","urls":{"html":"https://cve.report/CVE-2007-4970","api":"https://cve.report/api/cve/CVE-2007-4970.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4970","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4970"},"summary":{"title":"CVE-2007-4970","description":"ProcessGuard 3.410 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for Windows Native API functions including (1) NtCreateFile, (2) NtCreateKey, (3) NtDeleteValueKey, (4) NtOpenFile, (5) NtOpenKey, and (6) NtSetValueKey.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-09-19 01:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.4","severity":"","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","baseScore":4.4,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php","name":"http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Advisory 2007-09-18.01 - matousec.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/479830/100/0/threaded","name":"http://www.securityfocus.com/archive/1/479830/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php","name":"http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Plague in (security) software drivers - matousec.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/45954","name":"http://osvdb.org/45954","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/25714","name":"http://www.securityfocus.com/bid/25714","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"DiamondCS ProcessGuard SSDT Hooks Multiple Local Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4970","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4970","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4970","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"diamondcs","cpe5":"processguard","cpe6":"3.410","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:17:27.464Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"45954","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/45954"},{"name":"25714","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25714"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php"},{"name":"20070918 Plague in (security) software drivers & BSDOhook utility","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/479830/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-09-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"ProcessGuard 3.410 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for Windows Native API functions including (1) NtCreateFile, (2) NtCreateKey, (3) NtDeleteValueKey, (4) NtOpenFile, (5) NtOpenKey, and (6) NtSetValueKey."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"45954","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/45954"},{"name":"25714","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25714"},{"tags":["x_refsource_MISC"],"url":"http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php"},{"tags":["x_refsource_MISC"],"url":"http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php"},{"name":"20070918 Plague in (security) software drivers & BSDOhook utility","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/479830/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4970","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ProcessGuard 3.410 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for Windows Native API functions including (1) NtCreateFile, (2) NtCreateKey, (3) NtDeleteValueKey, (4) NtOpenFile, (5) NtOpenKey, and (6) NtSetValueKey."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"45954","refsource":"OSVDB","url":"http://osvdb.org/45954"},{"name":"25714","refsource":"BID","url":"http://www.securityfocus.com/bid/25714"},{"name":"http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php","refsource":"MISC","url":"http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php"},{"name":"http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php","refsource":"MISC","url":"http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php"},{"name":"20070918 Plague in (security) software drivers & BSDOhook utility","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/479830/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4970","datePublished":"2007-09-19T01:00:00.000Z","dateReserved":"2007-09-18T00:00:00.000Z","dateUpdated":"2024-08-07T15:17:27.464Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-09-19 01:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","baseScore":4.4,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:diamondcs:processguard:3.410:*:*:*:*:*:*:*","matchCriteriaId":"B2820834-A151-4FE4-A2AF-485766777D0A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4970","Ordinal":"1","Title":"CVE-2007-4970","CVE":"CVE-2007-4970","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4970","Ordinal":"1","NoteData":"ProcessGuard 3.410 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for Windows Native API functions including (1) NtCreateFile, (2) NtCreateKey, (3) NtDeleteValueKey, (4) NtOpenFile, (5) NtOpenKey, and (6) NtSetValueKey.","Type":"Description","Title":"CVE-2007-4970"},{"CveYear":"2007","CveId":"4970","Ordinal":"2","NoteData":"2007-09-18","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4970","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}