First published: Tue Jul 05 2005(Updated: )
The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an "allow" message to bypass a warning message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prevx Prevx Pro 2005 | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2145 is classified as a medium severity vulnerability.
To fix CVE-2005-2145, update to a patched version of Prevx Pro that addresses this kernel driver issue.
CVE-2005-2145 affects users running Prevx Pro 2005 version 1.0.
CVE-2005-2145 is a local privilege escalation vulnerability affecting the kernel driver.
An attacker can bypass the protection mechanisms of Prevx Pro 2005 by sending crafted messages to the driver.