Title : Motorola netOctopus Agent MSR Write Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2008-0062 CVE ID : CVE-2007-5761
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-01-08
Technical Description
A vulnerability has been identified in Motorola netOctopus, which could be exploited by local attackers to obtain elevated privileges. This issue is caused by an error in the "nantsys.sys" driver that exposes the writable "\\.\NantSys" device interface, which could be exploited by malicious users to execute arbitrary code with kernel privileges by manipulating the "SYSENTER_EIP_MSR" CPU Model Specific Register (MSR) value.