CVE-2007-5762: Input Validation
Published Jan 9, 2008
·Updated
NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHODNEITHER buffering mode.
Affected Software
1 affected component
Novell Netware Client=4.91-sp4
Remediation
Patch Available
Patch Available
Event History
Jan 9, 2008
CVE Published
10:46 PM
Jan 10, 2008
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5762?
CVE-2007-5762 is considered a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2007-5762?
To fix CVE-2007-5762, ensure that you update to a patched version of Novell NetWare Client beyond version 4.91 SP4.
3
Who is affected by CVE-2007-5762?
CVE-2007-5762 affects local users of Novell NetWare Client version 4.91 SP4 due to improper handling of IOCTL requests.
4
What type of vulnerability is CVE-2007-5762?
CVE-2007-5762 is classified as a local privilege escalation vulnerability.
5
Can CVE-2007-5762 be exploited remotely?
No, CVE-2007-5762 requires local access to the system to exploit the vulnerability.