PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-04-15 03:30
Updated : 2018-10-10 12:30
NVD link : CVE-2009-0681
Mitre link : CVE-2009-0681
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
pgp
- desktop