First published: Mon Mar 24 2008(Updated: )
The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | =vista | |
Microsoft Windows NT | =xp | |
Microsoft Windows 2000 | ||
Microsoft Windows Vista | ||
Microsoft Windows XP | ||
Panda Antivirus and Firewall | =2008 | |
Panda Security | =2008 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1471 has a high severity rating due to its potential to cause denial of service, system crashes, or arbitrary code execution.
To fix CVE-2008-1471, ensure that you update Panda Internet Security 2008 and Antivirus+ Firewall 2008 to the latest version provided by the vendor.
CVE-2008-1471 affects local users of Panda Internet Security 2008 and Antivirus+ Firewall 2008 on various versions of Microsoft Windows.
The vulnerable systems for CVE-2008-1471 include Panda Antivirus and Firewall 2008 running on Microsoft Windows XP and Vista.
CVE-2008-1471 is a local denial of service vulnerability that can lead to overwriting memory and executing arbitrary code through crafted IOCTL requests.