CVE-2007-4375
The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P
- Base score: 5.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.38%
- Percentile among all scored CVEs: 88
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · Diskeeper 9 - Remote Memory Disclosure (8/17/2007)
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065245.html
- http://osvdb.org/39546
- http://osvdb.org/39547
- http://secunia.com/advisories/26431
- http://securityreason.com/securityalert/3018
- http://www.securityfocus.com/archive/1/476954/100/0/threaded
- http://www.securityfocus.com/bid/25320
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36008
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065245.html
- http://osvdb.org/39546
- http://osvdb.org/39547
- http://secunia.com/advisories/26431
- http://securityreason.com/securityalert/3018
- http://www.securityfocus.com/archive/1/476954/100/0/threaded
- http://www.securityfocus.com/bid/25320
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36008
Raw JSON (NVD)
Show
{
"id": "CVE-2007-4375",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-08-16T18:17:00.000",
"references": [
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065245.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/39546",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/39547",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26431",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3018",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/476954/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25320",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36007",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36008",
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065245.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/39546",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/39547",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26431",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3018",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/476954/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/25320",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36007",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36008",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address."
},
{
"lang": "es",
"value": "La interfaz administrativa (también conocida como DkService.exe) en Diskeeper 9 Professional, 2007 Pro Premier, y probablemente otras versiones exponen una función de comparación de memoria a través de RPC sobre TCP, lo cual permite a atacantes remotos (1) obtener información sensible (contenidos de la memoria del proceso), como se ha demostrado con un ataque que obtiene la dirección base del módulo para vencer la aleatorización de la distribución del espacio de memoria (Address Space Layout Randomization o ASLR); o (2) provocar una denegación de servicio (caída de aplicación) mediante una dirección fuera de los límites."
}
],
"lastModified": "2026-06-16T22:43:57.633",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:diskeeper:diskeeper:9:*:professional:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72086DD7-EF2C-4347-8D43-07046DB0E3B3"
},
{
"criteria": "cpe:2.3:a:diskeeper:diskeeper:2007:*:pro_premier:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C0DFEEC-765C-46B5-80D2-F9913953024E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}