CVE-2007-1206
published 2007-04-10CVE-2007-1206: The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
2.71%
84.3th percentile
The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the "zero page" during a race condition before the view is unmapped.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_nt | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cjxh-xgwx-v2w6: Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2007-1973 [HIGH] GHSA-cjxh-xgwx-v2w6: Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4
Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206.
GHSA
GHSA-jc8m-fhw4-pp52: The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4
ghsa_unreviewed·2022-05-01
CVE-2007-1206 [HIGH] GHSA-jc8m-fhw4-pp52: The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4
The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the "zero page" during a race condition before the view is unmapped.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://research.eeye.com/html/advisories/published/AD20070410a.htmlhttp://secunia.com/advisories/24834http://securitytracker.com/id?1017898http://www.kb.cert.org/vuls/id/337953http://www.osvdb.org/34011http://www.securityfocus.com/archive/1/465232/100/0/threadedhttp://www.securityfocus.com/archive/1/466331/100/200/threadedhttp://www.securityfocus.com/bid/23367http://www.us-cert.gov/cas/techalerts/TA07-100A.htmlhttp://www.vupen.com/english/advisories/2007/1326https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-022https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1639http://research.eeye.com/html/advisories/published/AD20070410a.htmlhttp://secunia.com/advisories/24834http://securitytracker.com/id?1017898http://www.kb.cert.org/vuls/id/337953http://www.osvdb.org/34011http://www.securityfocus.com/archive/1/465232/100/0/threadedhttp://www.securityfocus.com/archive/1/466331/100/200/threadedhttp://www.securityfocus.com/bid/23367http://www.us-cert.gov/cas/techalerts/TA07-100A.htmlhttp://www.vupen.com/english/advisories/2007/1326https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-022https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1639
2007-04-10
Published