Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to cause a denial of service (system crash) via a crafted IOCTL call.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2009-03-14 18:30
Updated : 2024-02-04 17:33
NVD link : CVE-2009-0824
Mitre link : CVE-2009-0824
CVE.ORG link : CVE-2009-0824
JSON object : View
Products Affected
slysoft
- clonedvd
- virtualclonedrive
- clonecd
- anydvd
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer