CVE-2014-2382: High severity faronics deep freeze vulnerability
The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (crash) and execute arbitrary code via a crafted IOCTL request that writes to arbitrary memory locations, related to the IofCallDriver function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2382?
CVE-2014-2382 is classified as a high severity vulnerability due to its potential for causing denial of service and executing arbitrary code.
How do I fix CVE-2014-2382?
To fix CVE-2014-2382, upgrade to a version of Faronics Deep Freeze that is later than 8.10.
Who is affected by CVE-2014-2382?
CVE-2014-2382 affects local administrators using Faronics Deep Freeze Standard and Enterprise versions 8.10 and earlier.
What types of attacks can exploit CVE-2014-2382?
CVE-2014-2382 can be exploited through crafted IOCTL requests that lead to denial of service or arbitrary code execution.
What component of Faronics Deep Freeze is vulnerable in CVE-2014-2382?
CVE-2014-2382 affects the DfDiskLo.sys driver within Faronics Deep Freeze.