PT-2018-5053 · Dell · Invincea Dell Protected Workspace

CVE-2016-8732

·

Publicado

2018-04-24

·

Atualizado

2022-12-14

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Invincea Dell Protected Workspace version 5.1.1-22303
Description The issue is related to multiple security flaws in the InvProtectDrv.sys driver, which is part of the Invincea Dell Protected Workspace product. These flaws include weak restrictions on the driver communication channel and insufficient checks, allowing any application to disable some of the protection mechanisms provided by the product.
Recommendations For Invincea Dell Protected Workspace version 5.1.1-22303, consider restricting access to the InvProtectDrv.sys driver to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the vulnerable driver may help prevent the issue from being exploited. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8732

Produtos afetados

Invincea Dell Protected Workspace