VulnerabilityModified
CVE-2002-2127
Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.
LOW 2.1EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Affected
- pedestal software/integrity protection driver
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q4/0087.htmlPatch
- http://www.phrack.org/show.php?p=59&a=16
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10747
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q4/0087.htmlPatch
- http://www.phrack.org/show.php?p=59&a=16
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10747
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.