CVE-2003-1233
Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst command.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- pedestalsoftware/integrity protection driver
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.htmlBroken Link, Patch
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.htmlBroken Link, Exploit, Patch
- http://secunia.com/advisories/7816Broken Link, Patch, Vendor Advisory
- http://www.phrack.org/show.php?p=59&a=16Broken Link
- http://www.securityfocus.com/bid/6511Broken Link, Patch, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10979Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.htmlBroken Link, Patch
- http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.htmlBroken Link, Exploit, Patch
- http://secunia.com/advisories/7816Broken Link, Patch, Vendor Advisory
- http://www.phrack.org/show.php?p=59&a=16Broken Link
- http://www.securityfocus.com/bid/6511Broken Link, Patch, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10979Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.