CVE-2007-2523 affects CA Anti-Virus for the Enterprise r8 and Threat Manager r8, allowing local users to gain privileges. The vulnerability stems from weak permissions on a shared file mapping, which can be manipulated to trigger a stack-based buffer overflow in InoCore.dll. With a CVSS score of 7.2 (high severity), this flaw permits local attackers to achieve complete compromise of confidentiality, integrity, and availability with low attack complexity. While there is an ExploitDB entry for remote code execution, there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:a:broadcom:integrated_threat_management:8.0:*:*:*:*:*:*:* | ||
8CPE matchmatch criteria | cpe:2.3:a:ca:anti-virus_for_the_enterprise:8:*:enterprise:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.