4.9
CVSSv2

CVE-2008-0324

Published: 17/01/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 495
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco vpn client 5.0.2.0090

Exploits

/* cpndrv-dosc * * Copyright (c) 2008 by <mu-b@digit-labsorg> * * Cisco Systems VPN Client IPSec Driver local kernel system pool corruption POC * by mu-b - Sat 11 Jan 2008 * * - Tested on: CVPNDRVAsys 50020090 * * specifying an input buffer size less-than 8+31-bytes results in the * local kernel non-paged pool (METHOD_BUFFERED ...