7.2
CVSSv2

CVE-2009-4832

Published: 29/04/2010 Updated: 19/09/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80012010 request to the DLPCryptCore device.

Vulnerable Product Search on Vulmon Subscribe to Product

deslock deslock\\+ 4.0.2

Exploits

/* deslock-dlpcryptc * * Copyright (c) 2009 by <mu-b@digit-labsorg> * * DESlock+ 402 local kernel SYSTEM exploit * by mu-b - Thu 18 Jun 2009 * * - Tested on: dlpcryptsys 01127 * * text:0001BB2E: 'what do ya want for nothing?' * - hmmm, something that doesn't pass kernel mode pointers * between kernel and userland? * ...