CVE-2008-5724: High severity ESET Smart Security vulnerability
The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHODNEITHER IOCTL request to \Device\Epfw that overwrites portions of memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5724?
CVE-2008-5724 is considered a high severity vulnerability due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2008-5724?
To resolve CVE-2008-5724, upgrade ESET Smart Security to version 3.0.672.1 or later.
Which versions of ESET Smart Security are affected by CVE-2008-5724?
CVE-2008-5724 affects ESET Smart Security versions 3.0.672 and earlier.
What does CVE-2008-5724 exploit in ESET Smart Security?
CVE-2008-5724 exploits a vulnerability in the Personal Firewall driver epfw.sys that allows memory overwriting via crafted IRP requests.
Can CVE-2008-5724 be exploited remotely?
No, CVE-2008-5724 can only be exploited locally by users on the affected system.