PT-2016-4013 · Mcafee · Mcafee File Lock
Kyriakos Economou
·
Published
2016-01-29
·
Updated
2016-02-25
·
CVE-2015-8773
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
McAfee File Lock versions 5.x
Description
The issue is related to a stack-based buffer overflow in the McPvDrv.sys driver, which can cause a denial of service, resulting in a system crash. This occurs when a long vault GUID is passed in an ioctl call.
Recommendations
For McAfee File Lock version 5.x, update the McPvDrv.sys driver to a version that fixes the buffer overflow issue. As a temporary workaround, consider restricting the length of vault GUIDs passed to the ioctl call to prevent the buffer overflow.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee File Lock