The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to DeviceEpfw that overwrites portions of memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Smart_security | Eset | * | 3.0.672 (including) |
Smart_security | Eset | 3.0.551 (including) | 3.0.551 (including) |
Smart_security | Eset | 3.0.560 (including) | 3.0.560 (including) |
Smart_security | Eset | 3.0.563 (including) | 3.0.563 (including) |
Smart_security | Eset | 3.0.621 (including) | 3.0.621 (including) |
Smart_security | Eset | 3.0.642 (including) | 3.0.642 (including) |
Smart_security | Eset | 3.0.650 (including) | 3.0.650 (including) |
Smart_security | Eset | 3.0.657 (including) | 3.0.657 (including) |
Smart_security | Eset | 3.0.667 (including) | 3.0.667 (including) |
Smart_security | Eset | 3.0.669 (including) | 3.0.669 (including) |