PT-2011-2412 · Securstar · Securstar Drivecrypt
Published
2011-01-20
·
Updated
2011-01-21
·
CVE-2011-0513
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SecurStar DriveCrypt versions 5.4, 5.3, and earlier
Description
The issue allows local users to execute arbitrary code via a crafted argument to the 0x00073800 IOCTL, which is related to the DCR.sys driver in SecurStar DriveCrypt.
Recommendations
For SecurStar DriveCrypt versions 5.4, 5.3, and earlier, consider restricting access to the DCR.sys driver until a patch is available.
As a temporary workaround, avoid using the 0x00073800 IOCTL in the DCR.sys driver to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Securstar Drivecrypt