PGP Desktop 'PGPwded.sys' Local Code Execution Vulnerability
BID:32991
Info
PGP Desktop 'PGPwded.sys' Local Code Execution Vulnerability
| Bugtraq ID: | 32991 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 23 2008 12:00AM |
| Updated: | Apr 15 2009 04:16PM |
| Credit: | Giuseppe 'Evilcry' Bonfa' |
| Vulnerable: |
PGP Corporation PGP Desktop 9.9 build 397 PGP Corporation PGP Desktop 9.0.6 build 6060 PGP Corporation PGP Desktop 0 |
| Not Vulnerable: |
PGP Corporation PGP Desktop 9.10 |
Discussion
PGP Desktop 'PGPwded.sys' Local Code Execution Vulnerability
PGP Desktop is prone to a local code-execution vulnerability that occurs in the 'PGPwded.sys' driver.
A local attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Failed attacks will result in denial-of-service conditions.
Versions prior to PGP Desktop 9.10 are vulnerable.
PGP Desktop is prone to a local code-execution vulnerability that occurs in the 'PGPwded.sys' driver.
A local attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Failed attacks will result in denial-of-service conditions.
Versions prior to PGP Desktop 9.10 are vulnerable.
Exploit / POC
PGP Desktop 'PGPwded.sys' Local Code Execution Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
PGP Desktop 'PGPwded.sys' Local Code Execution Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
PGP Desktop 'PGPwded.sys' Local Code Execution Vulnerability
References:
References:
- PGP Desktop 9.0.6 Denial Of Service Vulnerability (Giuseppe �??Evilcry�?? Bonfa�??)
- PGP Desktop 9.10 - Resolved Issues (PGP Corporation)
- PGP Desktop Product Page (PGP Corporation)
- [Suspected Spam][Positive Technologies SA 2009-01] PGP Desktop Pgpdisk.sys And P ("Valery Marchuk"
) - PGP Desktop 9.0.6 Denial Of Service - ZeroDay ([email protected])