Invincea-X SboxDrv.sys Version... CVE-2016-9038 CNNVD-201707-079

4.4 AV AC AU C I A
发布: 2018-04-24
修订: 2022-12-13

### Summary An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer and race condition can result in kernel memory corruption, which could result in privilege escalation. An attacker needs to execute a special application locally to trigger this vulnerability. ### Tested Versions Invincea-X 6.1.3-24058 (Dell Protected Workspace) ### Product URLs https://www.invincea.com/solution-overview/ ### CVSSv3 Score 8.1 - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H ### Details This vulnerability is present in the SboxDrv.sys driver which is a part of Invincea-X (Dell Protected Workspace).This product provides sandbox functionality for Windows environments. Because of weak permissions set on the driver any malicious application can communicate with driver. The application can also provide pointer value that is double fetched in the kernel, allowing an attacker to cause a race condition resulting in...

0%
暂无可用Exp或PoC
当前有1条受影响产品信息