PT-2018-5053 · Dell · Invincea Dell Protected Workspace
CVE-2016-8732
·
Publicado
2018-04-24
·
Atualizado
2022-12-14
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Invincea Dell Protected Workspace version 5.1.1-22303
Description
The issue is related to multiple security flaws in the InvProtectDrv.sys driver, which is part of the Invincea Dell Protected Workspace product. These flaws include weak restrictions on the driver communication channel and insufficient checks, allowing any application to disable some of the protection mechanisms provided by the product.
Recommendations
For Invincea Dell Protected Workspace version 5.1.1-22303, consider restricting access to the InvProtectDrv.sys driver to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the vulnerable driver may help prevent the issue from being exploited. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Invincea Dell Protected Workspace