Vulnerabilities > CVE-2018-6322 - Unspecified vulnerability in Pandasecurity Panda Global Protection 17.0.1

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
pandasecurity

Summary

Panda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \.\pipe\PSANMSrvcPpal -- an "insecurely created named pipe." Ensures full access to Everyone users group.

Vulnerable Configurations

Part Description Count
Application
Pandasecurity
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/146708/TSI-ADV172018.txt
idPACKETSTORM:146708
last seen2018-03-23
published2018-03-08
reporterFelipe Xavier Oliveira
sourcehttps://packetstormsecurity.com/files/146708/Panda-Global-Security-17.0.1-NULL-DACL-Grants-Full-Access.html
titlePanda Global Security 17.0.1 NULL DACL Grants Full Access