CVE

Id
28396  
CVE No.
CVE-2007-5039  
Status
Candidate  
Description
Ghost Security Suite beta 1.110 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtQueryValueKey, (4) NtSetSystemInformation, and (5) NtSetValueKey kernel SSDT hooks.  
Phase
Assigned (20070923)  
Votes
None (candidate not yet proposed)  
Comments