Secunia Logo
 
CVE Reference: CVE-2007-5761
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5761

Description:
The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/39503

ST
  1019161

SAID
  Secunia Advisory: SA28366

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=636

CONFIRM
  http://www.netopia.com/support/software/technotes/netoctopus/Removing_the_nantsys_Driver.pdf

BID
  27175


Return to the previous page.