CVE-2008-3158 EXPLOIT
6.9
MEDIUM · CVSS 2.0 · EPSS 5.5% (pctl 93)
Patch early
A public exploit exists.
Description
Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.
Scoring
| CVSS | 6.9 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 5.48% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-07-11 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| novell | novell client for windows |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Novell Client 4.91 SP4 - 'nwfs.sys' Local Privilege Escalation (Metasploit) | 2013-06-24 |
References
- http://secunia.com/advisories/30904
- http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028543.html
- http://www.securityfocus.com/bid/30001
- http://www.securitytracker.com/id?1020385
- http://www.vupen.com/english/advisories/2008/1968/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43460
- http://secunia.com/advisories/30904
- http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028543.html
- http://www.securityfocus.com/bid/30001
- http://www.securitytracker.com/id?1020385
- http://www.vupen.com/english/advisories/2008/1968/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43460
→ the Explorer · watch your stack · NVD