CVE-2014-3752
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
01/02/2018
Last modified:
09/10/2018
Description
The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights to execute arbitrary code with SYSTEM privileges via a crafted 0x83170180 call.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:gdata-software:totalprotection:*:*:*:*:*:*:*:* | 24.0.2.1 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/127227/G-Data-TotalProtection-2014-Code-Execution.html
- http://seclists.org/fulldisclosure/2014/Jun/125
- http://www.securityfocus.com/archive/1/532559/100/0/threaded
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-3752/