LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2008-5724

CVE-2008-5724

CVSS 7.2 · HIGH

Summary

The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to \Device\Epfw that overwrites portions of memory.

CVSS 2.0 breakdown

Base score7.2 (HIGH)
VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Attack vectorLOCAL
Attack complexityLOW
ConfidentialityCOMPLETE
IntegrityCOMPLETE
AvailabilityCOMPLETE

Weakness type (CWE)

Affected products

Eset smart security
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-23. Always verify against the vendor advisory before acting.

Scroll to Top