CVE-2007-1537
\Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the…
Does this matter?
Lower severity and a low EPSS score (1.32%). Track it; it rarely justifies an emergency change on its own.
Description
\Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2003 server · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24598
- http://securityreason.com/securityalert/2471
- http://www.osvdb.org/33628
- http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=47
- http://www.securityfocus.com/archive/1/463208/100/0/threaded
- http://www.securityfocus.com/bid/23025
- http://www.vupen.com/english/advisories/2007/1031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33086
- http://secunia.com/advisories/24598
- http://securityreason.com/securityalert/2471
- http://www.osvdb.org/33628
- http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=47
- http://www.securityfocus.com/archive/1/463208/100/0/threaded
- http://www.securityfocus.com/bid/23025
- http://www.vupen.com/english/advisories/2007/1031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33086
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.