PT-2018-5053 · Dell · Invincea Dell Protected Workspace

Published

2018-04-24

·

Updated

2022-12-14

·

CVE-2016-8732

CVSS v3.1

7.8

High

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Invincea Dell Protected Workspace version 5.1.1-22303
Description The issue is related to multiple security flaws in the InvProtectDrv.sys driver, which is part of the Invincea Dell Protected Workspace product. These flaws include weak restrictions on the driver communication channel and insufficient checks, allowing any application to disable some of the protection mechanisms provided by the product.
Recommendations For Invincea Dell Protected Workspace version 5.1.1-22303, consider restricting access to the InvProtectDrv.sys driver to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the vulnerable driver may help prevent the issue from being exploited. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2016-8732

Affected Products

Invincea Dell Protected Workspace