4.9
CVSSv2

CVE-2009-0824

Published: 14/03/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 495
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and previous versions, as distributed in SlySoft AnyDVD prior to 6.5.2.6, Virtual CloneDrive 5.4.2.3 and previous versions, CloneDVD 2.9.2.0 and previous versions, and CloneCD 5.3.1.3 and previous versions, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to cause a denial of service (system crash) via a crafted IOCTL call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

slysoft anydvd

slysoft virtualclonedrive

slysoft clonedvd

slysoft clonecd

Exploits

source: wwwsecurityfocuscom/bid/34103/info Multiple SlySoft products are prone to multiple buffer-overflow vulnerabilities because they fail to adequately validate user-supplied input A local attacker can exploit these issues to execute arbitrary code with SYSTEM-level privileges Failed attacks will result in denial-of-service conditio ...

Recent Articles

The Slingshot APT FAQ
Securelist • Alexey Shulmin Sergey Yunakovsky Vasily Berdnikov Andrey Dolgushev • 09 Mar 2018

While analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file system, which is usually the sign of an advanced APT actor. This turned out to be a malicious loader internally named ‘Slingshot’, part of a new, and highly sophisticated attack platform that rivals Project Sauron and Regin in complexity. The initial loader replaces the victim´s legitimate Windows library ‘scesrv.dll’ with a malicious one of exactly th...