CVE-2004-2477
2.1 · LOWOverview
CVE-2004-2477 is a low-severity vulnerability affecting diamondcs process_guard_free. It was published on December 31, 2004 and has a CVSS 2.0 base score of 2.1 (LOW).
This vulnerability has a CVSS 2.0 base score of 2.1, rated LOW. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.
Technical Description
DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe.
Remediation
Check the references section for vendor advisories and patches from diamondcs. Update process_guard_free to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|
References
Frequently Asked Questions
What is CVE-2004-2477?
CVE-2004-2477 is a low-severity vulnerability affecting diamondcs process_guard_free. It was published on December 31, 2004 and has a CVSS 2.0 base score of 2.1 (LOW).
How severe is CVE-2004-2477?
This vulnerability has a CVSS 2.0 base score of 2.1, rated LOW. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.
How do I fix or remediate CVE-2004-2477?
Check the references section for vendor advisories and patches from diamondcs. Update process_guard_free to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2004-2477?
CyberStrike's AI-powered security agents can automatically detect CVE-2004-2477 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related LOW CVEs from 2004
View all →netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwr
A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the P
A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR env
Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code vi
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to
Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via
4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink att
Certain "programming errors" in the msync system call for FreeBSD 5.2.1 and earlier, and 4.10 and ea
MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world
Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to cre
IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite file
Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions ac