Vulnerabilities > CVE-2005-2145 - Local Security vulnerability in Prevx PRO 2005 1.0

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
prevx
nessus

Summary

The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an "allow" message to bypass a warning message.

Vulnerable Configurations

Part Description Count
Application
Prevx
1

Nessus

NASL familyWindows
NASL idPREVX_PRO_2005_MULT_VULNS.NASL
descriptionThe remote host is running Prevx Pro 2005, an intrusion protection system for Windows. The installed version of Prevx Pro 2005 reportedly suffers from multiple vulnerabilities that allow local attackers to bypass the application
last seen2020-06-01
modified2020-06-02
plugin id18616
published2005-07-05
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/18616
titlePrevx Pro 2005 <= 1.0.0.1 Multiple Vulnerabilities