First published: Fri Mar 02 2007(Updated: )
Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows attackers to produce malware that is more difficult to analyze.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Norman Norman Sandbox Analyzer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1194 is considered a moderate severity vulnerability due to its potential to allow local users to exploit the system environment.
To resolve CVE-2007-1194, ensure that you are using an updated version of Norman Sandbox Analyzer that addresses this vulnerability.
CVE-2007-1194 affects local users on systems running Norman Sandbox Analyzer that have not implemented the necessary security updates.
CVE-2007-1194 allows attackers to determine if the local machine is operating in a non-physical environment, which can facilitate targeted malware development.
CVE-2007-1194 specifically targets environments such as emulators that do not rely on a physical Intel processor.