{"api_version":"1","generated_at":"2026-07-23T10:23:57+00:00","cve":"CVE-2007-5762","urls":{"html":"https://cve.report/CVE-2007-5762","api":"https://cve.report/api/cve/CVE-2007-5762.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5762","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5762"},"summary":{"title":"CVE-2007-5762","description":"NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\\\.\\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-01-09 22:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id?1019172","name":"http://www.securitytracker.com/id?1019172","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NetWare 'nicm.sys' Driver Lets Local Users Gain Kernel Level Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=637","name":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=637","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://download.novell.com/Download?buildid=4FmI89wOmg4~","name":"http://download.novell.com/Download?buildid=4FmI89wOmg4~","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Downloads - Novell Client 4.91 Post-SP3/4 NICM.SYS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39576","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39576","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28396","name":"http://secunia.com/advisories/28396","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Novell Client nicm.sys Privilege Escalation Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0088","name":"http://www.vupen.com/english/advisories/2008/0088","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27209","name":"http://www.securityfocus.com/bid/27209","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Novell Client for Windows 'nicm.sys 'Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5762","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5762","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5762","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"netware_client","cpe6":"4.91","cpe7":"sp4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:39:13.723Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"27209","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27209"},{"name":"28396","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28396"},{"name":"ADV-2008-0088","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0088"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://download.novell.com/Download?buildid=4FmI89wOmg4~"},{"name":"20080109 Novell NetWare Client nicm.sys Local Privilege Escalation Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=637"},{"name":"novell-client-nicm-privilege-escalation(39576)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39576"},{"name":"1019172","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019172"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\\\.\\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"27209","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27209"},{"name":"28396","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28396"},{"name":"ADV-2008-0088","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0088"},{"tags":["x_refsource_CONFIRM"],"url":"http://download.novell.com/Download?buildid=4FmI89wOmg4~"},{"name":"20080109 Novell NetWare Client nicm.sys Local Privilege Escalation Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=637"},{"name":"novell-client-nicm-privilege-escalation(39576)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39576"},{"name":"1019172","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019172"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5762","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\\\.\\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27209","refsource":"BID","url":"http://www.securityfocus.com/bid/27209"},{"name":"28396","refsource":"SECUNIA","url":"http://secunia.com/advisories/28396"},{"name":"ADV-2008-0088","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0088"},{"name":"http://download.novell.com/Download?buildid=4FmI89wOmg4~","refsource":"CONFIRM","url":"http://download.novell.com/Download?buildid=4FmI89wOmg4~"},{"name":"20080109 Novell NetWare Client nicm.sys Local Privilege Escalation Vulnerability","refsource":"IDEFENSE","url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=637"},{"name":"novell-client-nicm-privilege-escalation(39576)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39576"},{"name":"1019172","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1019172"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5762","datePublished":"2008-01-09T22:00:00.000Z","dateReserved":"2007-10-31T00:00:00.000Z","dateUpdated":"2024-08-07T15:39:13.723Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-01-09 22:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:novell:netware_client:4.91:sp4:*:*:*:*:*:*","matchCriteriaId":"D33517C1-1716-4535-8AC6-FE6490FC5A39"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5762","Ordinal":"1","Title":"CVE-2007-5762","CVE":"CVE-2007-5762","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5762","Ordinal":"1","NoteData":"NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\\\.\\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode.","Type":"Description","Title":"CVE-2007-5762"},{"CveYear":"2007","CveId":"5762","Ordinal":"2","NoteData":"2008-01-09","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5762","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}