PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2009-04-15 10:30
Updated : 2024-02-04 17:33
NVD link : CVE-2009-0681
Mitre link : CVE-2009-0681
CVE.ORG link : CVE-2009-0681
JSON object : View
Products Affected
pgp
- desktop
CWE
CWE-20
Improper Input Validation