>> Novell Client for Windows "NWFS.SYS" Privilege Escalation Vulnerability
Title : Novell Client for Windows "NWFS.SYS" Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2008-1968 CVE ID : CVE-2008-3158 CWE ID : CWE-20
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-06-30
Technical Description
A vulnerability has been identified in Novell Client for Windows, which could be exploited by local attackers to obtain elevated privileges. This issue is caused by input validation errors in the "NWFS.SYS" driver when processing user-supplied data and IOCTL requests, which could be exploited by unprivileged users to overwrite arbitrary memory addresses and execute malicious code with elevated privileges.