PT-2017-9461 · Intel · Intel Security Data Loss Prevention Endpoint
Published
2017-03-14
·
Updated
2019-03-07
·
CVE-2016-8012
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Intel Security Data Loss Prevention Endpoint (DLPe) versions 9.3.600 through 9.4.200
Description
The issue allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process memory.
Recommendations
For versions 9.3.600 through 9.4.200, consider restricting access to the Read-Write-Execute permissions to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intel Security Data Loss Prevention Endpoint