First published: Wed Jan 09 2008(Updated: )
NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Client | =4.91-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5762 is considered a high severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2007-5762, ensure that you update to a patched version of Novell NetWare Client beyond version 4.91 SP4.
CVE-2007-5762 affects local users of Novell NetWare Client version 4.91 SP4 due to improper handling of IOCTL requests.
CVE-2007-5762 is classified as a local privilege escalation vulnerability.
No, CVE-2007-5762 requires local access to the system to exploit the vulnerability.