PT-2018-5053 · Dell · Invincea Dell Protected Workspace
Published
2018-04-24
·
Updated
2022-12-14
·
CVE-2016-8732
CVSS v3.1
7.8
High
| AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Invincea Dell Protected Workspace version 5.1.1-22303
Description
The issue is related to multiple security flaws in the InvProtectDrv.sys driver, which is part of the Invincea Dell Protected Workspace product. These flaws include weak restrictions on the driver communication channel and insufficient checks, allowing any application to disable some of the protection mechanisms provided by the product.
Recommendations
For Invincea Dell Protected Workspace version 5.1.1-22303, consider restricting access to the InvProtectDrv.sys driver to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the vulnerable driver may help prevent the issue from being exploited. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invincea Dell Protected Workspace