The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007...
Vulnerability Description
The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4375
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/25320
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36008
- http://osvdb.org/39546
- http://osvdb.org/39547
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065245.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36007
- http://secunia.com/advisories/26431
- http://www.securityfocus.com/archive/1/476954/100/0/threaded
- http://securityreason.com/securityalert/3018
Affected Vendor
diskeeper
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.