5.8
CVSSv2

CVE-2007-4375

Published: 16/08/2007 Updated: 15/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote malicious users to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.

Vulnerable Product Search on Vulmon Subscribe to Product

diskeeper diskeeper 9

diskeeper diskeeper 2007

Exploits

/* Diskeeper Remote Memory Disclosure Credit: Pravus (pravus -a-t- hush -d-o-t- com) Greetz: Scientology for making a remotely accessible disk defragmenter Felix, Jenna, and Isaac Vulnerability Description: This vulnerability involves a memory comparison function that is remotely, anonymously accessible via the remote procedure call in the Disk ...