CVE-2007-1194: Infoleak
Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows attackers to produce malware that is more difficult to analyze.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1194?
CVE-2007-1194 is considered a moderate severity vulnerability due to its potential to allow local users to exploit the system environment.
How do I fix CVE-2007-1194?
To resolve CVE-2007-1194, ensure that you are using an updated version of Norman Sandbox Analyzer that addresses this vulnerability.
Who is affected by CVE-2007-1194?
CVE-2007-1194 affects local users on systems running Norman Sandbox Analyzer that have not implemented the necessary security updates.
What does CVE-2007-1194 allow attackers to do?
CVE-2007-1194 allows attackers to determine if the local machine is operating in a non-physical environment, which can facilitate targeted malware development.
What environment does CVE-2007-1194 target?
CVE-2007-1194 specifically targets environments such as emulators that do not rely on a physical Intel processor.