PT-2011-2412 · Securstar · Securstar Drivecrypt
Publicado
2011-01-20
·
Atualizado
2011-01-21
·
CVE-2011-0513
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SecurStar DriveCrypt versions 5.4, 5.3, and earlier
Description
The issue allows local users to execute arbitrary code via a crafted argument to the 0x00073800 IOCTL, which is related to the DCR.sys driver in SecurStar DriveCrypt.
Recommendations
For SecurStar DriveCrypt versions 5.4, 5.3, and earlier, consider restricting access to the DCR.sys driver until a patch is available.
As a temporary workaround, avoid using the 0x00073800 IOCTL in the DCR.sys driver to minimize the risk of exploitation.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Securstar Drivecrypt