CVE-2007-1793 describes a local denial-of-service vulnerability, and potential arbitrary code execution, in the SPBBCDrv.sys driver used by various Symantec Norton products, including Personal Firewall 2006 and Internet Security 2008. The flaw stems from insufficient validation of arguments passed to hooked SSDT function handlers for NtCreateMutant and NtOpenEvent. This vulnerability has a CVSS score of 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C), indicating a local attack with low complexity, requiring no authentication, and primarily leading to a system crash. While no active exploitation is noted, a proof-of-concept for local denial of service exists on ExploitDB, but there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:a:symantec:antivirus:10.0:*:corporate:*:*:*:*:* | ||
10.0.1CPE matchmatch criteria | cpe:2.3:a:symantec:antivirus:10.0.1:*:corporate:*:*:*:*:* | ||
10.0.1.1CPE matchmatch criteria | cpe:2.3:a:symantec:antivirus:10.0.1.1:*:corporate:*:*:*:*:* | ||
10.0.2CPE matchmatch criteria | cpe:2.3:a:symantec:antivirus:10.0.2:*:corporate:*:*:*:*:* | ||
10.0.2.1CPE matchmatch criteria | cpe:2.3:a:symantec:antivirus:10.0.2.1:*:corporate:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.