Pedestal Software Integrity Protection Driver Bypass Vulnerability
BID:6295
Info
Pedestal Software Integrity Protection Driver Bypass Vulnerability
| Bugtraq ID: | 6295 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 02 2002 12:00AM |
| Updated: | Dec 02 2002 12:00AM |
| Credit: | Discovery credited to Jan Rutkowski <[email protected]>. |
| Vulnerable: |
Pedestal Software Integrity Protection Driver 1.2 |
| Not Vulnerable: |
Pedestal Software Integrity Protection Driver 1.3 |
Discussion
Pedestal Software Integrity Protection Driver Bypass Vulnerability
Pedestal Software's Integrity Protection Driver does not start until the system has been up for 20 minutes in order to allow the software to be uninstalled. During this time, an attacker who is able to gain privileged access to the system can set the system clock back to further delay the driver from starting.
This could allow an attacker a greater time window to perform modifications to the system before the driver starts.
Pedestal Software's Integrity Protection Driver does not start until the system has been up for 20 minutes in order to allow the software to be uninstalled. During this time, an attacker who is able to gain privileged access to the system can set the system clock back to further delay the driver from starting.
This could allow an attacker a greater time window to perform modifications to the system before the driver starts.
Exploit / POC
Pedestal Software Integrity Protection Driver Bypass Vulnerability
There is no exploit code necessary.
There is no exploit code necessary.
Solution / Fix
Pedestal Software Integrity Protection Driver Bypass Vulnerability
Solution:
This issue has been addressed in IPD 1.3:
Pedestal Software Integrity Protection Driver 1.2
Solution:
This issue has been addressed in IPD 1.3:
Pedestal Software Integrity Protection Driver 1.2
-
Pedestal Software Integrity Protection Driver 1.3
http://pedestalsoftware.com/download/ipd.zip
References
Pedestal Software Integrity Protection Driver Bypass Vulnerability
References:
References:
- Integrity Protection Driver (Pedestal Software)
- Bypassing Integrity Protection Driver (time vulnerability) (Jan Rutkowski
)