4.9
CVSSv2

CVE-2008-1141

Published: 04/03/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 500
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and previous versions allows local users to cause a denial of service (kernel memory consumption) via a series of DLMFENC_IOCTL requests to \\.\DLKPFSD_Device that allocate "link list structures."

Vulnerable Product Search on Vulmon Subscribe to Product

deslock deslock

Exploits

/* deslock-list-leakc * * Copyright (c) 2008 by <mu-b@digit-labsorg> * * DESlock+ <= 326 local kernel mem leak POC * by mu-b - Fri 21 Dec 2007 * * - Tested on: DLMFENCsys 10026 * * kernel pool memory leak by continually allocating link list * structures and never freeing them This is not without a sense * of irony in th ...
/* deslock-overflowc * * Copyright (c) 2008 by <mu-b@digit-labsorg> * * DESlock+ <= 327 local kernel overflow POC * by mu-b - Sat 23 Feb 2008 * * - Tested on: DLMFENCsys 10028 * * wwwcctmarkgovuk/CCTMAwards/DataEncryptionSystemsLtd/tabid/103/Defaultaspx * - I wonder what that says about CESG CCTM? * * - Pr ...