CVE-2007-0333
Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into the product's installation directory by creating links using FileLinkInformation requests with the ZwSetInformationFile function, as…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into the product's installation directory by creating links using FileLinkInformation requests with the ZwSetInformationFile function, as demonstrated by modifying SandBox.sys.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Affected
- agnitum/outpost firewall
- Source
- cve@mitre.org
References
- http://osvdb.org/33480
- http://securityreason.com/securityalert/2163
- http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.phpVendor Advisory
- http://www.securityfocus.com/archive/1/456973/100/0/threaded
- http://www.securityfocus.com/bid/22069Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31529
- http://osvdb.org/33480
- http://securityreason.com/securityalert/2163
- http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.phpVendor Advisory
- http://www.securityfocus.com/archive/1/456973/100/0/threaded
- http://www.securityfocus.com/bid/22069Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31529
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.