CORE FORCE before 0.95.172 does not properly validate arguments to...
Vulnerability Description
CORE FORCE before 0.95.172 does not properly validate arguments to SSDT hook handler functions in the Registry module, which allows local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-0366
Credits & Attribution
No credits recorded in the NVD database.
References
- http://force.coresecurity.com/index.php?module=articles&func=display&aid=32
- http://www.securityfocus.com/bid/27341
- http://www.securityfocus.com/archive/1/486513/100/0/threaded
- http://www.vupen.com/english/advisories/2008/0242
- http://www.coresecurity.com/?action=item&id=2025
- http://securityreason.com/securityalert/3555
- http://www.securitytracker.com/id?1019245
More from core security technologies
View All →Affected Vendor
core security technologies
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.