CVE-2014-2382

The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (crash) and execute arbitrary code via a crafted IOCTL request that writes to arbitrary memory locations, related to the IofCallDriver function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:faronics:deep_freeze:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:faronics:deep_freeze:*:*:*:*:standard:*:*:*

History

21 Nov 2024, 02:06

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/129172/Faronics-Deep-Freeze-Arbitrary-Code-Execution.html - Exploit () http://packetstormsecurity.com/files/129172/Faronics-Deep-Freeze-Arbitrary-Code-Execution.html - Exploit
References () http://seclists.org/fulldisclosure/2014/Nov/52 - Exploit () http://seclists.org/fulldisclosure/2014/Nov/52 - Exploit
References () https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2382/ - Exploit () https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2382/ - Exploit

Information

Published : 2014-11-20 13:55

Updated : 2024-11-21 02:06


NVD link : CVE-2014-2382

Mitre link : CVE-2014-2382

CVE.ORG link : CVE-2014-2382


JSON object : View

Products Affected

faronics

  • deep_freeze
CWE
CWE-399

Resource Management Errors