Vulnerabilities > CVE-2018-6322 - Unspecified vulnerability in Pandasecurity Panda Global Protection 17.0.1

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
pandasecurity

Summary

Panda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \.\pipe\PSANMSrvcPpal -- an "insecurely created named pipe." Ensures full access to Everyone users group.

Vulnerable Configurations

Part Description Count
Application
Pandasecurity
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/146708/TSI-ADV172018.txt
idPACKETSTORM:146708
last seen2018-03-23
published2018-03-08
reporterFelipe Xavier Oliveira
sourcehttps://packetstormsecurity.com/files/146708/Panda-Global-Security-17.0.1-NULL-DACL-Grants-Full-Access.html
titlePanda Global Security 17.0.1 NULL DACL Grants Full Access