Pedestal Software Integrity Protection Driver Symbolic Link Bypass Vulnerability
BID:6511
Info
Pedestal Software Integrity Protection Driver Symbolic Link Bypass Vulnerability
| Bugtraq ID: | 6511 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 03 2003 12:00AM |
| Updated: | Jan 03 2003 12:00AM |
| Credit: | Originally reported by crazylord <[email protected]>. |
| Vulnerable: |
Pedestal Software Integrity Protection Driver 1.3 Pedestal Software Integrity Protection Driver 1.2 |
| Not Vulnerable: |
Pedestal Software Integrity Protection Driver 1.4 |
Discussion
Pedestal Software Integrity Protection Driver Symbolic Link Bypass Vulnerability
Pedestal Software's Integrity Protection Driver protects the Windows kernel from being altered by malicious device drivers. This protection can be bypassed through the use of symbolic links.
By creating a symbolic link to the Windows drivers directory, an attacker can bypass the IPD and overwrite a driver file with a malicious file.
Pedestal Software's Integrity Protection Driver protects the Windows kernel from being altered by malicious device drivers. This protection can be bypassed through the use of symbolic links.
By creating a symbolic link to the Windows drivers directory, an attacker can bypass the IPD and overwrite a driver file with a malicious file.
Exploit / POC
Pedestal Software Integrity Protection Driver Symbolic Link Bypass Vulnerability
There is no exploit code necessary.
There is no exploit code necessary.
Solution / Fix
Pedestal Software Integrity Protection Driver Symbolic Link Bypass Vulnerability
Solution:
This issue was originally fixed in IPD 1.3, however, Jan Rutkowski <[email protected]> pointed out that by mapping the symbolic link to a drive letter using the subst command would bypass this fix.
Both exploitation methods have reportedly been addressed in IPD 1.4:
Pedestal Software Integrity Protection Driver 1.2
Pedestal Software Integrity Protection Driver 1.3
Solution:
This issue was originally fixed in IPD 1.3, however, Jan Rutkowski <[email protected]> pointed out that by mapping the symbolic link to a drive letter using the subst command would bypass this fix.
Both exploitation methods have reportedly been addressed in IPD 1.4:
Pedestal Software Integrity Protection Driver 1.2
-
Pedestal Software Integrity Protection Driver 1.4
http://www.pedestalsoftware.com/download/ipd.zip
Pedestal Software Integrity Protection Driver 1.3
-
Pedestal Software Integrity Protection Driver 1.4
http://www.pedestalsoftware.com/download/ipd.zip
References
Pedestal Software Integrity Protection Driver Symbolic Link Bypass Vulnerability
References:
References:
- Integrity Protection Driver (Pedestal Software)
- Playing with Windows /dev/(k)mem (crazylord
) - Another way to bypass Integrity Protection Driver ('subst' vuln) (Jan Rutkowski
) - Pedestal Software Security Notice ("Keith Woodard"
)