First published: Wed Dec 31 2003(Updated: )
The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack").
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alarm | =3.7.202 | |
Alarm | =3.7.211 | |
Alarm | =3.7.211 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2003-1309 is considered medium, as it allows local users to gain elevated privileges.
To fix CVE-2003-1309, update to the latest version of ZoneAlarm beyond 3.7.211, Pro 4.0.146.029, or Plus 4.0.146.029.
CVE-2003-1309 affects ZoneAlarm versions 3.7.211 and below, and Pro and Plus versions prior to 4.0.146.029.
The impact of CVE-2003-1309 is that it may allow local users to exploit the system to gain unauthorized privileges.
A workaround for CVE-2003-1309 is to restrict local user access and monitor system signals to prevent exploitation until a patch is applied.