vendor:
DESlock+
by:
mu-b
7.2
CVSS
HIGH
Kernel Ring0 Link List Zero
119
CWE
Product Name: DESlock+
Affected Version From: DESlock+ <= 3.2.6
Affected Version To: DESlock+ <= 3.2.6
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2008
DESlock+ <= 3.2.6 local kernel ring0 link list zero POC
DESlock+ is vulnerable to a local kernel ring0 link list zero vulnerability. This vulnerability allows an attacker to overwrite arbitrary memory locations in the kernel. This can be used to gain elevated privileges on the system.
Mitigation:
Upgrade to DESlock+ version 3.2.7 or later.