4 results (0.006 seconds)

CVSS: 2.1EPSS: 0%CPEs: 3EXPL: 1

The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument. • http://marc.info/?l=bugtraq&m=109276749821133&w=2 http://secunia.com/advisories/12169 http://www.ngsec.com/docs/advisories/NGSEC-2004-6.txt http://www.securityfocus.com/bid/10965 https://exchange.xforce.ibmcloud.com/vulnerabilities/17010 •

CVSS: 2.1EPSS: 0%CPEs: 2EXPL: 0

NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers using the subst command. • http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.html http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.html http://www.iss.net/security_center/static/10979.php http://www.securityfocus.com/bid/6511 •

CVSS: 2.1EPSS: 0%CPEs: 1EXPL: 0

Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink. • http://archives.neohapsis.com/archives/ntbugtraq/2002-q4/0087.html http://www.phrack.org/show.php?p=59&a=16 https://exchange.xforce.ibmcloud.com/vulnerabilities/10747 •

CVSS: 2.1EPSS: 0%CPEs: 1EXPL: 1

restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time. • http://archives.neohapsis.com/archives/bugtraq/2002-12/0021.html http://archives.neohapsis.com/archives/ntbugtraq/2002-q4/0087.html http://www.iss.net/security_center/static/10745.php http://www.securityfocus.com/bid/6295 •