CVE-2008-5725
Summary
| CVE | CVE-2008-5725 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-12-26 17:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The NT kernel-mode driver (aka pstrip.sys) 5.0.1.1 and earlier in EnTech Taiwan PowerStrip 3.84 and earlier allows local users to gain privileges via certain IRP parameters in an IOCTL request to \Device\Powerstrip1 that overwrites portions of memory. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Entechtaiwan | Powerstrip | 3.00 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.01 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.02 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.10 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.11 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.12 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.15 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.16 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.18 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.20 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.25 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.26 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.28 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.29 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.30 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.40 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.43 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.44 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.45 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.46 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.47 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.49 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.50 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.51 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.52 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.53 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.54 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.55 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.56 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.57 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.58 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.59 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.60 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.61 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.62 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.63 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.64 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.65 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.70 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.72 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.73 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.74 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.75 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.76 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.77 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.78 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.80 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.81 | All | All | All |
| Application | Entechtaiwan | Powerstrip | 3.83 | All | All | All |
| Application | Entechtaiwan | Powerstrip | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| NT Internals - PowerStrip (pstrip.sys) Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.ntinternals.org | Exploit |
| PowerStrip "pstrip.sys" IOCTL Handling Privilege Escalation - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| PowerStrip 'pstrip.sys' Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| PowerStrip < = 3.84 (pstrip.sys) Privilege Escalation Exploit - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| PowerStrip 3.84 - 'pstrip.sys' Local Privilege Escalation - Windows local Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.