First published: Wed Jul 11 2007(Updated: )
The IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver in WinPcap before 4.0.1 allows local users to overwrite memory and execute arbitrary code via malformed Interrupt Request Packet (Irp) parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libpcap | =4.0 | |
libpcap | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3681 is considered a high severity vulnerability due to its ability to allow local users to execute arbitrary code.
To fix CVE-2007-3681, update WinPcap to version 4.0.1 or later.
CVE-2007-3681 affects users of WinPcap versions 3.1 and 4.0.
The potential impacts of CVE-2007-3681 include memory overwrite and execution of arbitrary code leading to system compromise.
CVE-2007-3681 involves the IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver.