CVE-2007-1495 describes a denial of service vulnerability affecting Symantec Norton Personal Firewall 2006 (version 9.1.1.7) and potentially other products utilizing the symevent.sys driver (version 12.0.0.20). A local attacker can trigger a system crash by sending invalid data to the \Device\SymEvent driver via DeviceIoControl, effectively reintroducing a previously patched vulnerability (CVE-2006-4855). The vulnerability has a CVSS score of 4.9, indicating a medium severity. It requires local access (AV:L), has low attack complexity (AC:L), and does not require authentication (Au:N). The primary impact is a complete system denial of service (A:C), with no impact on confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting a low level of public awareness or interest in this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2006_9.1.1.7CPE matchmatch criteria | cpe:2.3:a:symantec:norton_personal_firewall:2006_9.1.1.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.