CVE-2007-4375 describes a vulnerability in the administrative interface (DkService.exe) of Diskeeper 9 Professional and 2007 Pro Premier, and likely other versions. This flaw exposes a memory comparison function via RPC over TCP, allowing remote attackers to either disclose sensitive process memory contents, including module base addresses to bypass ASLR, or trigger a denial of service through an application crash. With a CVSS score of 5.8, this vulnerability is network-exploitable with medium attack complexity and requires no authentication, leading to partial confidentiality and availability impacts. While not listed on CISA's KEV catalog, public exploit code exists on ExploitDB (EDB-4292), though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9CPE matchmatch criteria | cpe:2.3:a:diskeeper:diskeeper:9:*:professional:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:diskeeper:diskeeper:2007:*:pro_premier:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.