{"api_version":"1","generated_at":"2026-07-23T10:40:29+00:00","cve":"CVE-2007-5587","urls":{"html":"https://cve.report/CVE-2007-5587","api":"https://cve.report/api/cve/CVE-2007-5587.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5587","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5587"},"summary":{"title":"CVE-2007-5587","description":"Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-19 21:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.9","severity":"","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/26121","name":"http://www.securityfocus.com/bid/26121","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Macrovision SafeDisc SecDRV.SYS Method_Neither Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.reversemode.com/index.php?option=com_mamblog&Itemid=15&task=show&action=view&id=43&Itemid=15","name":"http://www.reversemode.com/index.php?option=com_mamblog&Itemid=15&task=show&action=view&id=43&Itemid=15","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"401 Unauthorized","mime":"text/xml","httpstatus":"401","archivestatus":"200"},{"url":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/privilege_escalation_exploit_i.html","name":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/privilege_escalation_exploit_i.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Security Response Weblog: Privilege Escalation Exploit In the Wild","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3537","name":"http://www.vupen.com/english/advisories/2007/3537","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37284","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37284","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/482482/100/0/threaded","name":"http://www.securityfocus.com/archive/1/482482/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.microsoft.com/technet/security/advisory/944653.mspx","name":"http://www.microsoft.com/technet/security/advisory/944653.mspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Your request has been blocked. This could be\r\n                        due to several reasons.","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/482474/100/0/threaded","name":"http://www.securityfocus.com/archive/1/482474/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4584","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4584","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27285","name":"http://secunia.com/advisories/27285","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Macrovision SafeDisc secdrv.sys Privilege Escalation - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-067","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-067","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS07-067 - Important | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/41429","name":"http://osvdb.org/41429","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-345A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-345A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-345A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/485268/100/0/threaded","name":"http://www.securityfocus.com/archive/1/485268/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blog.48bits.com/?p=172","name":"http://blog.48bits.com/?p=172","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"48Bits Blog  » Blog Archive   » Macrorisión – Windows XP/2k3 0bay","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/3266","name":"http://securityreason.com/securityalert/3266","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Windows XP/2003 Macrovision SecDrv.sys privilege escalation (0day) - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018833","name":"http://www.securitytracker.com/id?1018833","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Windows Macromedia Security Driver Buffer Overflow Lets Local Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5587","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5587","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5587","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"safedisc","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"5587","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"5587","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:39:13.262Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.reversemode.com/index.php?option=com_mamblog&Itemid=15&task=show&action=view&id=43&Itemid=15"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blog.48bits.com/?p=172"},{"name":"27285","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27285"},{"name":"944653","tags":["vendor-advisory","x_refsource_MSKB","x_transferred"],"url":"http://www.microsoft.com/technet/security/advisory/944653.mspx"},{"name":"oval:org.mitre.oval:def:4584","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4584"},{"name":"ADV-2007-3537","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3537"},{"name":"SSRT071506","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/485268/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/privilege_escalation_exploit_i.html"},{"name":"41429","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/41429"},{"name":"HPSBST02299","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/485268/100/0/threaded"},{"name":"TA07-345A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-345A.html"},{"name":"20071018 [CORRECTED] Microsoft Windows XP SP2/2003 - Macrovision SecDrv.sys privilege escalation (0day)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/482482/100/0/threaded"},{"name":"windows-secdrv-bo(37284)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37284"},{"name":"20071017 Microsoft Windows XP/2003 Macrovision SecDrv.sys privilege escalation (0day)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/482474/100/0/threaded"},{"name":"3266","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3266"},{"name":"1018833","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018833"},{"name":"26121","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26121"},{"name":"MS07-067","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-067"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.reversemode.com/index.php?option=com_mamblog&Itemid=15&task=show&action=view&id=43&Itemid=15"},{"tags":["x_refsource_MISC"],"url":"http://blog.48bits.com/?p=172"},{"name":"27285","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27285"},{"name":"944653","tags":["vendor-advisory","x_refsource_MSKB"],"url":"http://www.microsoft.com/technet/security/advisory/944653.mspx"},{"name":"oval:org.mitre.oval:def:4584","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4584"},{"name":"ADV-2007-3537","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3537"},{"name":"SSRT071506","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/485268/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/privilege_escalation_exploit_i.html"},{"name":"41429","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/41429"},{"name":"HPSBST02299","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/485268/100/0/threaded"},{"name":"TA07-345A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-345A.html"},{"name":"20071018 [CORRECTED] Microsoft Windows XP SP2/2003 - Macrovision SecDrv.sys privilege escalation (0day)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/482482/100/0/threaded"},{"name":"windows-secdrv-bo(37284)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37284"},{"name":"20071017 Microsoft Windows XP/2003 Macrovision SecDrv.sys privilege escalation (0day)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/482474/100/0/threaded"},{"name":"3266","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3266"},{"name":"1018833","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018833"},{"name":"26121","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26121"},{"name":"MS07-067","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-067"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5587","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.reversemode.com/index.php?option=com_mamblog&Itemid=15&task=show&action=view&id=43&Itemid=15","refsource":"MISC","url":"http://www.reversemode.com/index.php?option=com_mamblog&Itemid=15&task=show&action=view&id=43&Itemid=15"},{"name":"http://blog.48bits.com/?p=172","refsource":"MISC","url":"http://blog.48bits.com/?p=172"},{"name":"27285","refsource":"SECUNIA","url":"http://secunia.com/advisories/27285"},{"name":"944653","refsource":"MSKB","url":"http://www.microsoft.com/technet/security/advisory/944653.mspx"},{"name":"oval:org.mitre.oval:def:4584","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4584"},{"name":"ADV-2007-3537","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3537"},{"name":"SSRT071506","refsource":"HP","url":"http://www.securityfocus.com/archive/1/485268/100/0/threaded"},{"name":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/privilege_escalation_exploit_i.html","refsource":"MISC","url":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/privilege_escalation_exploit_i.html"},{"name":"41429","refsource":"OSVDB","url":"http://osvdb.org/41429"},{"name":"HPSBST02299","refsource":"HP","url":"http://www.securityfocus.com/archive/1/485268/100/0/threaded"},{"name":"TA07-345A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-345A.html"},{"name":"20071018 [CORRECTED] Microsoft Windows XP SP2/2003 - Macrovision SecDrv.sys privilege escalation (0day)","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/482482/100/0/threaded"},{"name":"windows-secdrv-bo(37284)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37284"},{"name":"20071017 Microsoft Windows XP/2003 Macrovision SecDrv.sys privilege escalation (0day)","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/482474/100/0/threaded"},{"name":"3266","refsource":"SREASON","url":"http://securityreason.com/securityalert/3266"},{"name":"1018833","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018833"},{"name":"26121","refsource":"BID","url":"http://www.securityfocus.com/bid/26121"},{"name":"MS07-067","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-067"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5587","datePublished":"2007-10-19T21:00:00.000Z","dateReserved":"2007-10-19T00:00:00.000Z","dateUpdated":"2024-08-07T15:39:13.262Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-19 21:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*","matchCriteriaId":"60EC86B8-5C8C-4873-B364-FB1F8EFE1CFF"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*","matchCriteriaId":"E61F1C9B-44AF-4B35-A7B2-948EEF7639BD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:safedisc:*:*:*:*:*:*:*:*","matchCriteriaId":"464B7EE8-CDDC-4A5D-BE9C-1E013733EB01"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5587","Ordinal":"1","Title":"CVE-2007-5587","CVE":"CVE-2007-5587","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5587","Ordinal":"1","NoteData":"Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.","Type":"Description","Title":"CVE-2007-5587"},{"CveYear":"2007","CveId":"5587","Ordinal":"2","NoteData":"2007-10-19","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5587","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}