Описание
The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.
Ссылки
- Vendor Advisory
- Patch
- Patch
- Patch
- ExploitPatch
- Vendor Advisory
- Patch
- Patch
- Patch
- ExploitPatch
Уязвимые конфигурации
Конфигурация 1
Одновременно
Одно из
cpe:2.3:o:microsoft:windows-nt:vista:*:x32:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:*:x32:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:*:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:x64:*:*:*:*:*
Одно из
cpe:2.3:a:panda:panda_antivirus_and_firewall:2008:*:*:*:*:*:*:*
cpe:2.3:a:panda:panda_internet_security:2008:*:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.00251
Низкий
7.2 High
CVSS2
Дефекты
CWE-399
Связанные уязвимости
github
почти 4 года назад
The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.
EPSS
Процентиль: 48%
0.00251
Низкий
7.2 High
CVSS2
Дефекты
CWE-399