CVE-2003-1233

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
31/12/2003
Last modified:
16/02/2024

Description

Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pedestalsoftware:integrity_protection_driver:*:*:*:*:*:*:*:* 1.3 (including)