Vulnerabilities > Pedestal Software > Integrity Protection Driver > 1.2

DATE CVE VULNERABILITY TITLE RISK
2004-08-17 CVE-2004-1718 Local Denial Of Service vulnerability in Pedestal Software Integrity Protection Driver 1.2/1.3/1.4
The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument.
local
low complexity
pedestal-software
2.1
2003-12-31 CVE-2003-1246 Symbolic Link Bypass vulnerability in Pedestal Software Integrity Protection Driver 1.2/1.3
NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers using the subst command.
local
low complexity
pedestal-software
2.1
2002-12-31 CVE-2002-2127 Local Security vulnerability in Pedestal Software Integrity Protection Driver 1.2
Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.
local
low complexity
pedestal-software
2.1
2002-12-31 CVE-2002-2126 Unspecified vulnerability in Pedestal Software Integrity Protection Driver 1.2
restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.
local
low complexity
pedestal-software
2.1