Unrated severityNVD Advisory· Published Sep 24, 2007· Updated Apr 23, 2026
CVE-2007-5047
CVE-2007-5047
Description
Norton Internet Security 2008 15.0.0.60 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the NtOpenSection kernel SSDT hook. NOTE: the NtCreateMutant and NtOpenEvent function hooks are already covered by CVE-2007-1793.
Affected products
1- cpe:2.3:a:symantec:norton_internet_security:2008_15.0.0.60:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.matousec.com/info/advisories/plague-in-security-software-drivers.phpnvdVendor Advisory
- www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.phpnvdVendor Advisory
- osvdb.org/45897nvd
- securityreason.com/securityalert/3161nvd
- www.securityfocus.com/archive/1/479830/100/0/threadednvd
News mentions
0No linked articles in our index yet.