7.2

CVE-2011-0513

Exploit
DCR.sys driver in SecurStar DriveCrypt 5.4, 5.3, and earlier allows local users to execute arbitrary code via a crafted argument to the 0x00073800 IOCTL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SecurstarDrivecrypt Version <= 5.4
SecurstarDrivecrypt Version4.6
SecurstarDrivecrypt Version4.61
SecurstarDrivecrypt Version5.0
SecurstarDrivecrypt Version5.1
SecurstarDrivecrypt Version5.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.98% 0.574
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://osvdb.org/70426
http://secunia.com/advisories/42881
Vendor Advisory
http://www.exploit-db.com/exploits/15972
Exploit
http://www.securityfocus.com/bid/45750
Exploit
http://www.vupen.com/english/advisories/2011/0084
Vendor Advisory