CVE-2009-0824
14.03.2009, 18:30
Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to cause a denial of service (system crash) via a crafted IOCTL call.Enginsight
Vendor | Product | Version |
---|---|---|
slysoft | anydvd | 𝑥 ≤ 6.5.2.2 |
slysoft | clonecd | 𝑥 ≤ 5.3.1.3 |
slysoft | clonedvd | 𝑥 ≤ 2.9.2.0 |
slysoft | virtualclonedrive | 𝑥 ≤ 5.4.2.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References