CVE-2008-1736: High severity comodo firewall pro vulnerability
Comodo Firewall Pro before 3.0 does not properly validate certain parameters to hooked System Service Descriptor Table (SSDT) functions, which allows local users to cause a denial of service (system crash) via (1) a crafted OBJECTATTRIBUTES structure in a call to the NtDeleteFile function, which leads to improper validation of a ZwQueryObject result; and unspecified calls to the (2) NtCreateFile and (3) NtSetThreadContext functions, different vectors than CVE-2007-0709.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1736?
CVE-2008-1736 has a severity rating that indicates it can cause a denial of service, resulting in system crashes.
How do I fix CVE-2008-1736?
To resolve CVE-2008-1736, it is recommended to upgrade to Comodo Firewall Pro version 3.0 or later.
Who is affected by CVE-2008-1736?
CVE-2008-1736 affects local users of Comodo Firewall Pro versions prior to 3.0.
What causes the vulnerability in CVE-2008-1736?
CVE-2008-1736 is caused by improper validation of parameters to hooked System Service Descriptor Table functions.
What actions should be taken if CVE-2008-1736 is exploited?
If CVE-2008-1736 is exploited, immediate system updates should be applied, and careful monitoring for unusual activity should be conducted.