Invincea Dell Protected Workspace... CVE-2016-8732 CNNVD-201707-080

4.6 AV AC AU C I A
发布: 2018-04-24
修订: 2022-12-14

### Summary Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver communication channel and additonal insufficient checks allow any application to turn off some of the protection mechanisms provided by the Invincea product. ### Tested Versions Invincea Dell Protected Workspace build 5.1.1-22303 ### Product URLs * http://www.dellprotectedworkspace.com/ * https://www.invincea.com ### CVSSv3 Score 7.8 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H ### Details This vulnerability is present in the InvProtectDrv.sys driver which is a part of the Invincea Dell Protected Workspace. This product provides sandbox functionality for Windows environments. Due to weak permissions on the driver communication channel and ineffective additional checks, any malicious application can communicate with driver and turn off some of the security functionality provided by this product. Let's investigate these...

0%
暂无可用Exp或PoC
当前有1条受影响产品信息